PT-2026-95139 · Sqlbot+1 · Sqlbot+1
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
SQLBot versions prior to 1.9.0
Description
SQLBot is a Text-to-SQL system utilizing large language models and Retrieval-Augmented Generation (RAG). An authenticated user can submit a crafted
tableName value within the Excel datasource configuration via the 'POST /api/v1/datasource/' endpoint. The system stores this value without proper identifier handling. When the datasource is subsequently deleted using the 'DELETE /api/v1/datasource/{id}' endpoint, the stored value is interpolated into the cleanup SQL and executed by PostgreSQL. This second-order SQL injection allows the invocation of the PostgreSQL COPY TO PROGRAM command, enabling the execution of arbitrary operating-system commands with the privileges of the postgres process within the SQLBot container.Recommendations
Update to version 1.9.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postgresql
Sqlbot