PT-2026-94065 · Coze Dev+1 · Coze-Studio
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Coze Studio versions prior to 0.5.2
Description
Authenticated attackers can execute SQL statements against memory databases of other workspaces to read, insert, or delete data. This occurs because the software fails to validate that table names used in workflow SQL customization nodes belong to the caller's workspace, allowing the enumeration of predictable table identifiers.
Recommendations
Update Coze Studio to version 0.5.2 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coze-Studio