Impact
An issue in SQLite before the Fossil check‑in 869a51ae84df allows a local attacker to obtain sensitive information by manipulating the Session Extension changeset concat/changegroup merge path. The flaw is a buffer‑access weakness that can leak confidential data stored in the database to the user executing the database.
Affected Systems
The vulnerability affects the SQLite database engine. Any application that incorporates a SQLite build released prior to the check‑in, regardless of vendor, is potentially impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium‑to‑high severity vulnerability, while the EPSS score of < 1% shows a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, meaning no publicly known exploits exist. An attacker would need local file‑system access and the ability to influence the Session Extension merge path; the attack remains local and requires sufficient privileges to invoke or modify the database engine.
OpenCVE Enrichment