PT-2026-98197 · Db Hub · Db Hub
CVE-2026-61788
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
DBHub versions prior to 0.22.6
Description
Setting
readonly = true on the execute sql tool fails to enforce a read-only connection. The database-level read-only controls are not activated because the required configuration value is never populated. Instead, the system relies on a classifier that only inspects the first keyword of each statement. Consequently, any SELECT statement that triggers side effects through function calls is permitted.Depending on the database role, this can lead to sequence tampering or, with privileged roles, arbitrary file writes on the server via
lo export(), reading arbitrary host files via pg read file(), and remote code execution using dblink combined with COPY ... TO PROGRAM. Additionally, the HTTP transport is unauthenticated and binds to 0.0.0.0 by default, making the /mcp endpoint accessible to any network caller.Recommendations
Update DBHub to version 0.22.6.
As a temporary workaround, avoid using the
execute sql tool with readonly = true for sensitive database roles until the update is applied.Exploit
Fix
RCE
Incorrect Authorization
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db Hub