Unknown · Openchatbi · CVE-2026-84061
**Name of the Vulnerable Software and Affected Versions**
zhongyu09 OpenChatBI versions prior to 1.0.0b1
**Description**
A remote SQL injection flaw exists in the ` validate sql safety()` function within the openchatbi/text2sql/generate sql.py file. This issue occurs because the SQL safety validation is either entirely absent or incomplete, allowing an attacker to manipulate queries remotely.
**Recommendations**
Update to version 1.0.0b1 or later.
As a temporary workaround, restrict access to the ` validate sql safety()` function to minimize the risk of exploitation.