Impact
SQLBot’s /api/v1/datasource/parseExcel endpoint writes attacker‑controlled multipart filenames to a fixed directory before validation, allowing a double‑extension file such as malicious.py.exe to be stored as a Python source in /opt/sqlbot/app/alembic/versions/. This directory is imported by Alembic during application startup or migration, so the uploaded file is executed with the process’s privileges, giving the attacker arbitrary code execution. The flaw is an insecure file path write (CWE‑22).
Affected Systems
All versions of Dataease’s SQLBot released before 1.9.0 are affected, as the vulnerability resides in backend/apps/datasource/api/datasource.py and affects any instance exposing the parseExcel endpoint.
Risk and Exploitability
The CVSS base score is 7.3, indicating significant exploitation potential, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker must submit a crafted multipart upload to the parseExcel endpoint. Based on the description, it is inferred that authenticated access to the API may be required, but this detail is not explicitly stated in the CVE data. Once the file is written, the attacker’s code is executed at import time, providing remote code execution without additional privileges.
OpenCVE Enrichment