Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/SQLBot

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.

Join the discussion

CVE-2026-53557 is a high-severity SQL injection vulnerability in dataease SQLBot versions prior to 1.9.0. An authenticated user can supply a crafted tableName value in the Excel datasource configuration, which is stored without proper sanitization. Later, when the datasource is deleted, this stored value is interpolated into a SQL cleanup command executed by PostgreSQL, enabling second-order SQL injection. This can lead to arbitrary operating system command execution with the privileges of the postgres process inside the SQLBot container. The issue is fixed in version 1.9.0.

Join the discussion

CVE-2026-53555 is a stored cross-site scripting (XSS) vulnerability in dataease SQLBot versions prior to 1.9.0. An authenticated user can upload an SVG image containing malicious JavaScript via a PATCH request. The application stores this SVG without sanitization and later serves it inline, allowing the embedded script to execute in the context of other users' sessions. This can lead to unauthorized actions and data access within the victim's session. The issue is fixed in version 1.9.0.

Join the discussion

CVE-2026-53556 is an SQL injection vulnerability in dataease SQLBot prior to version 1.9.0. The issue occurs in the POST /api/v1/datasource/previewData endpoint, where the client-controlled table_name parameter is incorporated into SQL queries without proper safe identifier handling. This allows an authenticated user to execute read-only SELECT operations that can invoke PostgreSQL functions to read filesystem contents. In default configurations, the internal PostgreSQL connection accepts invalid credentials and runs with superuser privileges, potentially exposing sensitive files such as /etc/hosts and /etc/passwd. The vulnerability is fixed in version 1.9.0.

Join the discussion

CVE-2026-53554 is a path traversal vulnerability in dataease SQLBot versions prior to 1.9.0. The issue occurs in the POST /api/v1/datasource/parseExcel endpoint, which improperly uses attacker-controlled multipart filename data to determine where uploaded files are stored. This allows an attacker to place malicious files in the Alembic migration directory, which are then executed during SQLBot startup or migration processing. The vulnerability is fixed in version 1.9.0.

Join the discussion

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users viewing the dashboard.

Join the discussion

SQLBot versions prior to 1.8.0 contain an authorization bypass vulnerability classified as CWE-639 (Authorization Bypass Through User-Controlled Key). This vulnerability affects the /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoints, allowing an attacker with limited privileges to access and modify database schemas and data sources belonging to other tenants or workspaces. The issue is fixed in version 1.8.0. The CVSS 4.0 base score is 8.6, indicating a high severity vulnerability.

Join the discussion

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the SQL extracted from the LLM response is executed against the database without validation or sanitization. An authenticated attacker can craft a malicious question to manipulate the LLM into generating and executing arbitrary SQL statements. When connected to a PostgreSQL data source, this can lead to remote code execution via COPY FROM PROGRAM. This issue has been fixed in version 1.7.1.

Join the discussion

A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of the file backend/apps/db/es_engine.py of the component Elasticsearch Handler. This manipulation of the argument address causes server-side request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.7.0 is capable of addressing this issue. You should upgrade the affected component. The vendor was contacted early about this disclosure.

Join the discussion

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user (even the lowest-privileged) to fully compromise the backend server. The root cause is twofold: Excel Sheet names are concatenated directly into PostgreSQL table names without sanitization (datasource.py#L351), and those table names are embedded into COPY SQL statements via f-strings instead of parameterized queries (datasource.py#L385-L388). An attacker can bypass the 31-character Sheet name limit using a two-stage technique—first uploading a normal file whose data rows contain shell commands, then uploading an XML-tampered file whose Sheet name injects a TO PROGRAM 'sh' clause into the SQL. Confirmed impacts include arbitrary command execution as the postgres user (uid=999), sensitive file exfiltration (e.g., /etc/passwd, /etc/shadow), and complete PostgreSQL database takeover. This issue has been fixed in version 1.7.0.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Package: pkg:github/SQLBot
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses