PT-2026-96301 · Chartbrew · Chartbrew

CVE-2026-61852

·

Published

2026-09-21

·

Updated

2026-09-30

CVSS v4.0

5.8

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 5.2.2
Description The runQuery() function in server/modules/ai/orchestrator/tools/runQuery.js fails to perform runtime integer validation on the row limit parameter before interpolating it into a SQL LIMIT clause. Because the read-only keyword check occurs before this value is appended, an authenticated user capable of influencing a model-generated non-integer row limit can inject SQL to bypass the check. This allows the execution of arbitrary statements against the connected database, which may lead to unauthorized data access, data modification, file access, or the execution of operating-system commands depending on database permissions.
Recommendations Update to version 5.2.2.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61852
GHSA-4923-M569-JC42

Affected Products

Chartbrew