Fit2cloud
Fit2cloud Sqlbot: vulnerabilidades y CVE
Fit2cloud Sqlbot tiene 14 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses14
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-93660 | Alta (7.1) | 0.43% | — | 18 sept 2026 | SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply… |
| CVE-2026-53557 | Alta (7.7) | 0.34% | — | 17 sept 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted… |
| CVE-2026-53556 | Media (6) | 0.48% | — | 17 sept 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the… |
| CVE-2026-53555 | Media (5.1) | 0.48% | — | 17 sept 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and… |
| CVE-2026-53554 | Alta (7.3) | 0.41% | — | 17 sept 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled… |
| CVE-2026-72743 | Media (5.1) | 0.30% | — | 10 ago 2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can… |
| CVE-2026-42463 | Alta (8.6) | 0.36% | — | 13 may 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the… |
| CVE-2026-33324 | Crítica (9.4) | 0.84% | — | 5 may 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is… |
| CVE-2026-32950 | Alta (8.6) | 1.0% | — | 20 mar 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables… |
| CVE-2026-32949 | Alta (8.7) | 0.48% | — | 20 mar 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system… |
| CVE-2026-32622 | Alta (8.6) | 0.77% | — | 19 mar 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the… |
| CVE-2025-15598 | Baja (2.9) | 0.19% | — | 3 mar 2026 | A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation… |
| CVE-2025-15597 | Baja (2.1) | 0.56% | — | 2 mar 2026 | A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access… |
| CVE-2025-69285 | Alta (7.7) | 0.46% | — | 21 ene 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.