Description
bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Apply Patch
AI Analysis

Impact

A SQL injection flaw in the /utils/sql-parser.ts component of Bytebase dbhub version 1.2.0 allows an attacker to send crafted SQL statements that are executed against the database. Because the input is not properly validated or parameterized, the attacker can read or otherwise manipulate data that should be protected, compromising confidentiality and potentially integrity of the database.

Affected Systems

Bytebase dbhub version 1.2.0 is impacted, with the vulnerability located in the /utils/sql-parser.ts component. This component is accessible via a web endpoint, allowing attackers to target the application if the endpoint is exposed to the network.

Risk and Exploitability

The flaw is a classic SQL injection (CWE‑89). No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. SQL injection offers an attacker the ability to read or modify data, jeopardizing confidentiality and integrity. The attack requires remote access to the vulnerable endpoint; no authentication is needed if the endpoint is publicly reachable. Until a vendor patch is released, the risk is considered significant for any systems running the affected version.

Generated by OpenCVE AI on September 30, 2026 at 04:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a patched version of Bytebase dbhub that addresses the SQL injection flaw as soon as it becomes available
  • If an update is not yet possible, block or restrict access to the /utils/sql-parser endpoint to only trusted administrative users or mitigate further by implementing an access control list
  • Apply generic input validation or use parameterized queries on the server side to prevent injection if the code can be modified

Generated by OpenCVE AI on September 30, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in Bytebase dbhub V1.2.0 Allows Data Exposure
Weaknesses CWE-89

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-29T19:15:29.070Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79536

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T20:17:27.253

Modified: 2026-09-29T20:17:27.253

Link: CVE-2026-79536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T04:45:19Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')