PT-2026-57262 · Clickhouse+2 · Clickhouse+2

·

CVE-2026-61461

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dify versions prior to 1.16.0-rc1
Description A SQL injection issue exists in the MyScale vector store backend. This occurs when unsanitized search parameters are passed to the search by full text() function without proper escaping or parameterization. This flaw allows attackers to execute arbitrary SQL commands to read, modify, or delete data within the underlying ClickHouse database.
Recommendations Update Dify to version 1.16.0-rc1 or later. As a temporary mitigation, restrict access to the search by full text() function in the MyScale vector store backend.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61461

Affected Products

Clickhouse
Dify
Myscale