Description
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value without safe identifier handling. When the same datasource is later removed through DELETE /api/v1/datasource/{id}, the stored value is interpolated into datasource cleanup SQL and executed by PostgreSQL. This second-order SQL injection can invoke PostgreSQL COPY TO PROGRAM and execute arbitrary operating-system commands with the privileges of the postgres process inside the SQLBot container. This issue is fixed in version 1.9.0.
Published: 2026-09-17
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Patch
AI Analysis

Impact

SQLBot, a large‑language‑model powered Text‑to‑SQL tool, contained a second‑order SQL injection flaw that allowed an authenticated user to inject arbitrary SQL by supplying a crafted table name in an Excel datasource. Because the value was stored verbatim and later interpolated into a cleanup query, an attacker could cause PostgreSQL to execute the COPY TO PROGRAM command, resulting in arbitrary operating‑system command execution with the privileges of the postgres process running inside the SQLBot container.

Affected Systems

DataEase’s SQLBot product is affected. Any installation of SQLBot earlier than version 1.9.0 is vulnerable. The flaw is triggered when a user creates an Excel datasource via the POST /api/v1/datasource/ endpoint and later deletes the datasource through DELETE /api/v1/datasource/{id}. Only deployments that expose these API endpoints and allow authenticated users to create and delete datasources are at risk, regardless of the underlying PostgreSQL database version.

Risk and Exploitability

With a CVSS score of 7.7 and an EPSS of less than 1 %, the flaw represents a moderate‑to‑high severity risk. The likely attack vector is an authenticated user with permissions to create and delete datasources through the REST API. Once those conditions are met, the second‑order injection can be triggered automatically, enabling the attacker to execute arbitrary shell commands on the host running the PostgreSQL instance inside the SQLBot container. The vulnerability is not yet listed in CISA’s KEV catalog, and no widespread public exploitation is reported at this time, but the potential impact of remote command execution warrants immediate remediation.

Generated by OpenCVE AI on September 19, 2026 at 01:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SQLBot to version 1.9.0 or later, where the unsafe identifier handling has been removed.
  • Restrict datasource creation and deletion permissions to trusted administrators, preventing ordinary users from supplying untrusted table names.
  • Revoke or disable the PostgreSQL COPY TO PROGRAM command for the SQLBot database user and run PostgreSQL with the minimal privileges required by the application.

Generated by OpenCVE AI on September 19, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Dataease
Dataease sqlbot
Vendors & Products Dataease
Dataease sqlbot

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/datasource/, and SQLBot stores that value without safe identifier handling. When the same datasource is later removed through DELETE /api/v1/datasource/{id}, the stored value is interpolated into datasource cleanup SQL and executed by PostgreSQL. This second-order SQL injection can invoke PostgreSQL COPY TO PROGRAM and execute arbitrary operating-system commands with the privileges of the postgres process inside the SQLBot container. This issue is fixed in version 1.9.0.
Title SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T01:54:15.476Z

Reserved: 2026-06-09T18:13:07.263Z

Link: CVE-2026-53557

cve-icon Vulnrichment

Updated: 2026-09-22T01:54:09.618Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:00.243

Modified: 2026-09-23T17:17:49.530

Link: CVE-2026-53557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')