CVE-2025-15597

MEDIUM

Dataease SQLBot <1.4.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.0 mitigates this issue. The name of the patch is d640ac31d1ce64ce90e06cf7081163915c9fc28c. Upgrading the affected component is recommended. Multiple endpoints are affected. The vendor was contacted early about this disclosure.

References (17)

Core 17
Core References
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707293
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.348291
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.348291
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.706144
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707283
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707284
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707285
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707286
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707288
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707294
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707295
Various Sources product
https://github.com/dataease/SQLBot/

Scores

CVSS v3 6.3
EPSS 0.0055
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (1)
fit2cloud/sqlbot < 1.5.0
Published Mar 02, 2026
Tracked Since Mar 02, 2026