Impact
SQLBot, a large‑language‑model powered Text‑to‑SQL tool, contained a second‑order SQL injection flaw that allowed an authenticated user to inject arbitrary SQL by supplying a crafted table name in an Excel datasource. Because the value was stored verbatim and later interpolated into a cleanup query, an attacker could cause PostgreSQL to execute the COPY TO PROGRAM command, resulting in arbitrary operating‑system command execution with the privileges of the postgres process running inside the SQLBot container.
Affected Systems
DataEase’s SQLBot product is affected. Any installation of SQLBot earlier than version 1.9.0 is vulnerable. The flaw is triggered when a user creates an Excel datasource via the POST /api/v1/datasource/ endpoint and later deletes the datasource through DELETE /api/v1/datasource/{id}. Only deployments that expose these API endpoints and allow authenticated users to create and delete datasources are at risk, regardless of the underlying PostgreSQL database version.
Risk and Exploitability
With a CVSS score of 7.7 and an EPSS of less than 1 %, the flaw represents a moderate‑to‑high severity risk. The likely attack vector is an authenticated user with permissions to create and delete datasources through the REST API. Once those conditions are met, the second‑order injection can be triggered automatically, enabling the attacker to execute arbitrary shell commands on the host running the PostgreSQL instance inside the SQLBot container. The vulnerability is not yet listed in CISA’s KEV catalog, and no widespread public exploitation is reported at this time, but the potential impact of remote command execution warrants immediate remediation.
OpenCVE Enrichment