PT-2026-96300 · Chartbrew · Chartbrew

CVE-2026-61851

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

6.5

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 5.2.2
Description An authenticated user with AI feature access can execute dangerous statements or database functions because the runQuery() function in server/modules/ai/orchestrator/tools/runQuery.js uses an insufficient blocklist of only seven SQL keywords to enforce read-only database access. This allows the execution of unauthorized commands without needing SQL injection or keyword-obfuscation. Depending on the database engine, configuration, and user privileges, this could lead to file exposure or modification, access to internal network resources, changes to database privileges, command execution, or data alteration.
Recommendations Update to version 5.2.2. As a temporary workaround, restrict access to the AI features or the runQuery() function until the update is applied.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61851
GHSA-CP8J-2XWC-HXG8

Affected Products

Chartbrew