« Volver al listado

Fit2cloud

Fit2cloud Sqlbot: vulnerabilidades y CVE

Fit2cloud Sqlbot tiene 14 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses14
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-93660Alta (7.1)0.43%—18 sept 2026
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply…
CVE-2026-53557Alta (7.7)0.34%—17 sept 2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted…
CVE-2026-53556Media (6)0.48%—17 sept 2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the…
CVE-2026-53555Media (5.1)0.48%—17 sept 2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and…
CVE-2026-53554Alta (7.3)0.41%—17 sept 2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled…
CVE-2026-72743Media (5.1)0.30%—10 ago 2026
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can…
CVE-2026-42463Alta (8.6)0.36%—13 may 2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass vulnerability in the…
CVE-2026-33324Crítica (9.4)0.84%—5 may 2026
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is…
CVE-2026-32950Alta (8.6)1.0%—20 mar 2026
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables…
CVE-2026-32949Alta (8.7)0.48%—20 mar 2026
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system…
CVE-2026-32622Alta (8.6)0.77%—19 mar 2026
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the…
CVE-2025-15598Baja (2.9)0.19%—3 mar 2026
A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation…
CVE-2025-15597Baja (2.1)0.56%—2 mar 2026
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access…
CVE-2025-69285Alta (7.7)0.46%—21 ene 2026
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services7
  2. T1005 Data from Local System3
  3. T1059 Command and Scripting Interpreter3
  4. T1059.007 JavaScript2
  5. T1190 Exploit Public-Facing Application2
  6. T1565.001 Stored Data Manipulation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Fit2cloud