Impact
kaiten versions from 57.192.20 up to but not including 57.214.26 are vulnerable to SQL injection because dynamic SQL statements are built without proper data validation or the use of parameterized queries or stored procedures, allowing an attacker to inject arbitrary SQL. This flaw can lead to unauthorized data read, modification, or deletion, resulting in loss or alteration of confidential information. The vulnerability is a classic example of injection weaknesses.
Affected Systems
The affected product is kaiten, a data ingestion tool, with impacted versions ranging from 57.192.20 through 57.214.25. Versions prior to 57.192.20 and 57.214.26 or later are not known to be vulnerable.
Risk and Exploitability
EPSS score of 0.00215 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, the nature of the flaw—unsanitized user input in SQL queries—typically carries a high potential for attack if the application is exposed to untrusted data. The likely attack vector is through any endpoint that accepts user-supplied parameters without validation, but specific exploitation steps are not detailed in the advisory. Given these uncertainties, an assessment of the overall risk would be high in environments where kaiten processes sensitive or high-volume data. The CVSS score is 9.9, which denotes critical severity.
OpenCVE Enrichment