Impact
Anyquery is an SQL query engine built on top of SQLite. Prior to version 0.4.5, anyquery forwards unauthenticated SQL from its MySQL‑compatible server port to SQLite without restricting the ATTACH DATABASE command. A remote attacker can select any path writable by the Anyquery server process, causing SQLite to create a database file there that contains attacker‑controlled table data. This allows arbitrary file creation or overwrite, which can lead to filesystem integrity loss and denial of service. Remote code execution is possible only when another service interprets the written file or the process has a privileged writable target. This issue is fixed in version 0.4.5.
Affected Systems
The product affected is Anyquery, a server‑side SQL engine built on SQLite by the vendor julien040. All releases before 0.4.5 are vulnerable. The vulnerability is mitigated in any release 0.4.5 or later.
Risk and Exploitability
The CVSS score for this issue is 9.1, indicating a high‑severity attack path. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, yet the flaw remains serious because it allows unauthenticated remote execution via the database server port. The flaw is not listed in the CISA KEV catalog, but the low EPSS score does not diminish the potential impact. A remote attacker can exploit this through the MySQL‑compatible interface, which is typically exposed on TCP port 3306, and since no authentication is required, the attack vector is to a target path that is writable by the Anyquery process; if that path is privileged or subsequently interpreted by another service, remote code execution can occur.
OpenCVE Enrichment
Github GHSA