Description
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A low-privileged bearer-token holder can invoke the function through the /v1/query HTTP endpoint, causing path.Join to resolve .. segments outside $XDG_CACHE_HOME/anyquery/plugins/ and os.RemoveAll to recursively delete any reachable directory writable by the Anyquery server process. This causes permanent data loss and denial of service without disclosing file contents. This issue is fixed in version 0.4.5.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Directory Deial of Service
Action: Apply Patch
AI Analysis

Impact

The clear_plugin_cache scalar function in Anyquery accepts a caller‑controlled plugin name and passes it to path.Join before calling os.RemoveAll, without rejecting traversal segments. An attacker with a bearer‑token who can invoke the function via the /v1/query HTTP endpoint can supply a plugin string containing ".." segments that resolve to locations outside $XDG_CACHE_HOME/anyquery/plugins/. The resulting call to os.RemoveAll will recursively delete any reachable directory writable by the Anyquery server process, leading to permanent data loss and denial of service, with no disclosure of file contents.

Affected Systems

Anyquery, versions earlier than 0.4.5, deployed by the vendor julien040. Any installation that exposes the /v1/query endpoint with bearer-token authentication is susceptible.

Risk and Exploitability

The flaw carries a CVSS score of 7.3, indicating high impact. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the issue is not listed in the CISA KEV catalog. Attackers holding a low‑privileged bearer token can invoke the vulnerable function over HTTP, making exploitation straightforward in exposed environments.

Generated by OpenCVE AI on September 20, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Anyquery to version 0.4.5 or later to incorporate the fix.
  • If an immediate upgrade is not possible, restrict or remove bearer‑token access to the /v1/query endpoint or disable the clear_plugin_cache function.
  • Ensure the plugin cache directory is stored in a protected location and set write to directories outside the designated cache path.

Generated by OpenCVE AI on September 20, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j9rx-rppg-6hh4 Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Julien040
Julien040 anyquery
Vendors & Products Julien040
Julien040 anyquery

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A low-privileged bearer-token holder can invoke the function through the /v1/query HTTP endpoint, causing path.Join to resolve .. segments outside $XDG_CACHE_HOME/anyquery/plugins/ and os.RemoveAll to recursively delete any reachable directory writable by the Anyquery server process. This causes permanent data loss and denial of service without disclosing file contents. This issue is fixed in version 0.4.5.
Title Anyquery: Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory Deletion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Julien040 Anyquery
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:09:37.157Z

Reserved: 2026-05-18T22:54:18.273Z

Link: CVE-2026-47253

cve-icon Vulnrichment

Updated: 2026-09-14T20:09:12.304Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:44.070

Modified: 2026-09-30T19:08:43.927

Link: CVE-2026-47253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')