PT-2026-96300 · Chartbrew · Chartbrew
CVE-2026-61851
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
6.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Chartbrew versions prior to 5.2.2
Description
An authenticated user with AI feature access can execute dangerous statements or database functions because the
runQuery() function in server/modules/ai/orchestrator/tools/runQuery.js uses an insufficient blocklist of only seven SQL keywords to enforce read-only database access. This allows the execution of unauthorized commands without needing SQL injection or keyword-obfuscation. Depending on the database engine, configuration, and user privileges, this could lead to file exposure or modification, access to internal network resources, changes to database privileges, command execution, or data alteration.Recommendations
Update to version 5.2.2.
As a temporary workaround, restrict access to the AI features or the
runQuery() function until the update is applied.Exploit
Fix
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chartbrew