Description
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content is stored, writes the content before spreadsheet parsing and validation finish, and can transform a double-extension filename into a Python source file. An attacker able to submit a crafted multipart upload can use these behaviors to place attacker-controlled content in /opt/sqlbot/app/alembic/versions/ even when a spreadsheet parsing failure after the file write causes the endpoint to return an error. The planted file remains on disk, and subsequent SQLBot startup or migration processing causes Alembic to import the module and execute its module-level statements in the SQLBot application runtime. This issue is fixed in version 1.9.0.
Published: 2026-09-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

SQLBot’s /api/v1/datasource/parseExcel endpoint writes attacker‑controlled multipart filenames to a fixed directory before validation, allowing a double‑extension file such as malicious.py.exe to be stored as a Python source in /opt/sqlbot/app/alembic/versions/. This directory is imported by Alembic during application startup or migration, so the uploaded file is executed with the process’s privileges, giving the attacker arbitrary code execution. The flaw is an insecure file path write (CWE‑22).

Affected Systems

All versions of Dataease’s SQLBot released before 1.9.0 are affected, as the vulnerability resides in backend/apps/datasource/api/datasource.py and affects any instance exposing the parseExcel endpoint.

Risk and Exploitability

The CVSS base score is 7.3, indicating significant exploitation potential, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker must submit a crafted multipart upload to the parseExcel endpoint. Based on the description, it is inferred that authenticated access to the API may be required, but this detail is not explicitly stated in the CVE data. Once the file is written, the attacker’s code is executed at import time, providing remote code execution without additional privileges.

Generated by OpenCVE AI on September 19, 2026 at 01:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SQLBot version 1.9.0 or newer to apply the vendor patch that removes the insecure file write.
  • Restrict the parseExcel endpoint to trusted users or IP ranges and monitor for suspicious uploads.
  • Audit the /opt/sqlbot/app/alembic/versions/ directory for unintended .py files, delete any that appear suspicious, and, if possible, disable automatic migration imports until the patch is deployed.
  • (Optional) As a temporary fix modify the backend code to reject double‑extension filenames, sanitize paths, or use a secure temp directory instead of the migration folder.

Generated by OpenCVE AI on September 19, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Dataease
Dataease sqlbot
Vendors & Products Dataease
Dataease sqlbot

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename data when selecting where uploaded content is stored, writes the content before spreadsheet parsing and validation finish, and can transform a double-extension filename into a Python source file. An attacker able to submit a crafted multipart upload can use these behaviors to place attacker-controlled content in /opt/sqlbot/app/alembic/versions/ even when a spreadsheet parsing failure after the file write causes the endpoint to return an error. The planted file remains on disk, and subsequent SQLBot startup or migration processing causes Alembic to import the module and execute its module-level statements in the SQLBot application runtime. This issue is fixed in version 1.9.0.
Title SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:16:54.601Z

Reserved: 2026-06-09T18:13:07.263Z

Link: CVE-2026-53554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:16:59.770

Modified: 2026-09-23T17:17:49.923

Link: CVE-2026-53554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:15:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')