Impact
Anyquery is an SQL engine built on SQLite. In versions prior to 0.4.5 the server exposes file-backed SQLite virtual table modules, notably csv_reader and log_reader, through its MySQL-compatible port without authentication, authorization, or directory restrictions. A remote attacker can issue a CREATE VIRTUAL TABLE statement specifying a local path; the module uses hashicorp/go-getter to read the file and returns its contents as queryable table rows. This capability allows reading any file the Anyquery server process can access, potentially leaking system configuration, credentials, or private keys.
Affected Systems
The issue affects all earlier releases of anyquery from the vendor julien040 whose server exposes the csv_reader and log_reader virtual table modules through the MySQL-compatible port. Versions before 0.4.5 are vulnerable. The problem is limited to server mode running as that vendor’s binaries; client-only usage is unaffected.
Risk and Exploitability
The vulnerability scores 7.5 on CVSS, indicating a high to medium severity. Because the server module is exposed without authentication or authorization, an attacker who can reach the MySQL-compatible port could craft a CREATE VIRTUAL TABLE statement that points to any path accessible by the server process. The EPSS score of less than 1% indicates a very low exploitation probability, but if an attacker has network access to the port the risk remains because the vulnerability is not trivial to exploit and allows extraction of any file the server process can read, including configuration files, credentials, or private keys.
OpenCVE Enrichment
Github GHSA