Sqlbot · Sqlbot · CVE-2026-53556
**Name of the Vulnerable Software and Affected Versions**
SQLBot versions prior to 1.9.0
**Description**
An issue exists where the `POST /api/v1/datasource/previewData` endpoint incorporates the client-controlled `table name` value into generated SQL without safe identifier handling. An authenticated user can configure a datasource for the internal PostgreSQL service and submit a crafted `table name` to invoke functions such as `pg read file()`, `pg read binary file()`, or `pg ls dir()`, while remaining a SELECT operation under the read-only policy. In default trusted loopback authentication configurations, the internal connection may execute with PostgreSQL superuser privileges, allowing the retrieval of filesystem content, including `/etc/hosts` and `/etc/passwd`, potentially exposing configuration, credentials, authentication secrets, and source code.
**Recommendations**
Update to version 1.9.0.
Avoid using the `table name` parameter in the `POST /api/v1/datasource/previewData` endpoint until the update is applied.