Description
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can configure a datasource for SQLBot's internal PostgreSQL service and submit a crafted table_name that remains a SELECT operation under the read-only policy while invoking pg_read_file(), pg_read_binary_file(), or pg_ls_dir(). In the default tested trusted loopback authentication configuration, the internal connection accepts invalid credentials and executes with PostgreSQL superuser privileges, allowing filesystem content such as /etc/hosts and /etc/passwd to be returned in the previewData API response and potentially exposing configuration, credentials, authentication secrets, and source code. This issue is fixed in version 1.9.0.
Published: 2026-09-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file read via authenticated SQL injection
Action: Immediate Patch
AI Analysis

Impact

An authenticated user can send a crafted table_name parameter to the previewData POST endpoint, which is included verbatim in a SELECT statement without safe identifier handling. The reflected payload can invoke PostgreSQL functions such as pg_read_file, pg_read_binary_file, or pg_ls_dir, allowing the attacker to read any file from the server that the database or the executing environment can access. This means configuration files, credentials, and source code may be exposed, compromising confidentiality and potentially allowing further system compromise. The weakness is a classic SQL injection (CWE‑89).

Affected Systems

The vulnerability exists in SQLBot versions prior to 1.9.0. It affects the backend component dataease:SQLBot that exposes the /api/v1/datasource/previewData API. Users running the default trusted loopback authentication configuration are at the greatest risk because the internal PostgreSQL connection can accept invalid credentials and run with superuser privileges. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 6 indicates a moderate severity; the EPSS score is less than 1 %, suggesting a low probability of active exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the exploit requires authentication to the API, possession of a datasource configuration, and a trusted network configuration that allows superuser-level database access. An attacker meeting these conditions can read arbitrary files but cannot immediately execute code or modify data unless further privilege escalation is achieved. The risk remains moderate until the official patch is applied or a workaround limits the ability to invoke privileged PostgreSQL functions.

Generated by OpenCVE AI on September 19, 2026 at 01:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SQLBot to version 1.9.0 or later, where the unsafe identifier handling is fixed.
  • Reconfigure the internal PostgreSQL connection so that trusted loopback authentication does not grant superuser privileges; use role‑based access control and ensure the previewData endpoint runs with read‑only rights.
  • Disable or remove the PostgreSQL functions pg_read_file, pg_read_binary_file, and pg_ls_dir from the database role that the service uses if an upgrade cannot be applied immediately.

Generated by OpenCVE AI on September 19, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Dataease
Dataease sqlbot
Vendors & Products Dataease
Dataease sqlbot

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can configure a datasource for SQLBot's internal PostgreSQL service and submit a crafted table_name that remains a SELECT operation under the read-only policy while invoking pg_read_file(), pg_read_binary_file(), or pg_ls_dir(). In the default tested trusted loopback authentication configuration, the internal connection accepts invalid credentials and executes with PostgreSQL superuser privileges, allowing filesystem content such as /etc/hosts and /etc/passwd to be returned in the previewData API response and potentially exposing configuration, credentials, authentication secrets, and source code. This issue is fixed in version 1.9.0.
Title SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:01:34.847Z

Reserved: 2026-06-09T18:13:07.263Z

Link: CVE-2026-53556

cve-icon Vulnrichment

Updated: 2026-09-18T20:01:30.656Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:00.073

Modified: 2026-09-23T17:17:49.503

Link: CVE-2026-53556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')