Impact
Anyquery is an SQL query engine built on SQLite. Prior to version 0.4.5, the Anyquery server exposes URL‑capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL‑compatible server port without restricting outbound destinations. A remote attacker can supply a loopback, private‑network, or link‑local cloud metadata URL, causing go‑getter in the Anyquery server process to fetch the selected resource and expose its response as queryable table data. This permits internal network probing, access to internal APIs, and disclosure of cloud credentials; low‑integrity impact is possible when the accessed internal API performs state‑changing actions. The issue is fixed in version 0.4.5.
Affected Systems
julien040's Anyquery server releases prior to version 0.4.5, which expose the URL‑capable virtual table modules via the unauthenticated MySQL‑compatible server port, are affected. No more specific version numbers are listed beyond the reference to prior to 0.4.5.
Risk and Exploitability
With a CVSS score of 8.6, the flaw is high severity. An EPSS score of < 1% indicates a low exploitation probability, and the issue is not listed in CISA KEV. The likely attack vector is via an unauthenticated connection to the MySQL‑compatible server port, enabling a remote attacker to trigger outbound HTTP requests with no additional privileges.
OpenCVE Enrichment
Github GHSA