๐Ÿ” CVE Alert

CVE-2026-61851

UNKNOWN 0.0

Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js attempts to enforce read-only database access with a blocklist containing only seven SQL keywords. An authenticated user with AI feature access can submit dangerous statements or database functions that are absent from the read-only keyword blocklist, causing them to execute without SQL injection or keyword-obfuscation techniques. Depending on the database engine, configuration, and database-user privileges, this can expose or write files, access internal network resources, change database privileges, execute commands, or alter data. This issue is fixed in version 5.2.2.

CWE CWE-184
Vendor chartbrew
Product chartbrew
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for chartbrew chartbrew

Be the first to know when new unknown vulnerabilities affecting chartbrew chartbrew are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

chartbrew / chartbrew
< 5.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/chartbrew/chartbrew/security/advisories/GHSA-cp8j-2xwc-hxg8 github.com: https://github.com/chartbrew/chartbrew/commit/8c8412edce56093e81b524e0235a796c7dd42336 github.com: https://github.com/chartbrew/chartbrew/releases/tag/v5.2.2