PT-2026-95137 · Sqlbot · Sqlbot

·

CVE-2026-53555

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions SQLBot versions prior to 1.9.0
Description An authenticated uploader can upload an image/svg+xml assistant UI logo via the 'PATCH /api/v1/system/assistant/ui' endpoint. The system stores the SVG without sanitizing or validating embedded active content. The file is subsequently served inline from the same application origin through the 'GET /api/v1/system/assistant/picture/{filename}' endpoint. When another user loads this resource, embedded JavaScript executes within the web application context, leading to stored cross-site scripting (XSS), which allows access to the data and actions of the victim's session.
Recommendations Update to version 1.9.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53555
GHSA-V23M-5PVQ-XCGX

Affected Products

Sqlbot