PT-2026-57262 · Clickhouse+2 · Clickhouse+2
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dify versions prior to 1.16.0-rc1
Description
A SQL injection issue exists in the MyScale vector store backend. This occurs when unsanitized search parameters are passed to the
search by full text() function without proper escaping or parameterization. This flaw allows attackers to execute arbitrary SQL commands to read, modify, or delete data within the underlying ClickHouse database.Recommendations
Update Dify to version 1.16.0-rc1 or later.
As a temporary mitigation, restrict access to the
search by full text() function in the MyScale vector store backend.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clickhouse
Dify
Myscale