Description
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the SVG without sanitizing or validating embedded active content. SQLBot later serves the file inline from the same application origin through GET /api/v1/system/assistant/picture/{filename}. When another user loads that generated resource, JavaScript embedded in the SVG executes in the SQLBot web application context, resulting in stored cross-site scripting with access to data and actions available to the victim's session. This issue is fixed in version 1.9.0.
Published: 2026-09-17
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting
Action: Patch
AI Analysis

Impact

The flaw exists because SQLBot accepts SVG files uploaded by an authenticated user without sanitizing them, stores the file, and later serves it inline from the same origin. When an attacker uploads a crafted SVG containing malicious JavaScript, any subsequent user who views the logo has that JavaScript executed with the victim’s session privileges. This allows the attacker to read confidential data, manipulate the application, or perform arbitrary actions with the victim’s rights.

Affected Systems

SQLBot by DataEase, versions prior to 1.9.0, are affected. The flaw is present in the assistant UI logo upload API /api/v1/system/assistant/ui and is remedied in release 1.9.0; older installations remain vulnerable until upgraded.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1 % shows a low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack requires an authenticated session with permission to upload the SVG logo, meaning an attacker must first compromise or obtain credentials for a user who has that privilege. If successful, the stored XSS can be triggered by any other logged‑in user who views the image, allowing an attacker to execute arbitrary scripts in their browser context.

Generated by OpenCVE AI on September 19, 2026 at 00:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SQLBot to version 1.9.0 or newer, which removes the unsanitized SVG handling.
  • Restrict the ability to upload assistant UI logos to administrators or users with non‑trusted roles.
  • Implement input sanitization for all SVG uploads to strip or neutralize embedded JavaScript before storage or when serving the image.

Generated by OpenCVE AI on September 19, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Dataease
Dataease sqlbot
Vendors & Products Dataease
Dataease sqlbot

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the SVG without sanitizing or validating embedded active content. SQLBot later serves the file inline from the same application origin through GET /api/v1/system/assistant/picture/{filename}. When another user loads that generated resource, JavaScript embedded in the SVG executes in the SQLBot web application context, resulting in stored cross-site scripting with access to data and actions available to the victim's session. This issue is fixed in version 1.9.0.
Title Stored XSS via SVG Upload
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:14:53.154Z

Reserved: 2026-06-09T18:13:07.263Z

Link: CVE-2026-53555

cve-icon Vulnrichment

Updated: 2026-09-18T13:14:46.634Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:16:59.917

Modified: 2026-09-23T17:17:49.950

Link: CVE-2026-53555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:15:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')