PT-2026-95139 · Sqlbot+1 · Sqlbot+1

·

CVE-2026-53557

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SQLBot versions prior to 1.9.0
Description SQLBot is a Text-to-SQL system utilizing large language models and Retrieval-Augmented Generation (RAG). An authenticated user can submit a crafted tableName value within the Excel datasource configuration via the 'POST /api/v1/datasource/' endpoint. The system stores this value without proper identifier handling. When the datasource is subsequently deleted using the 'DELETE /api/v1/datasource/{id}' endpoint, the stored value is interpolated into the cleanup SQL and executed by PostgreSQL. This second-order SQL injection allows the invocation of the PostgreSQL COPY TO PROGRAM command, enabling the execution of arbitrary operating-system commands with the privileges of the postgres process within the SQLBot container.
Recommendations Update to version 1.9.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53557
GHSA-VXWJ-843F-9C9G

Affected Products

Postgresql
Sqlbot