Description
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.0 mitigates this issue. The name of the patch is d640ac31d1ce64ce90e06cf7081163915c9fc28c. Upgrading the affected component is recommended. Multiple endpoints are affected. The vendor was contacted early about this disclosure.
References (17)
Core 17
Core References
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707293
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.348291
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.348291
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.706144
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707283
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707284
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707285
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707286
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707288
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707294
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.707295
Exploit, Third Party Advisory exploit
https://github.com/yaowenxiao721/Poc/blob/main/SQLBot/SQLBot-User-Management-Broken-Access-Control.md
Vendor Advisory related
https://github.com/dataease/SQLBot/security/advisories/GHSA-h4xm-3q3p-5g6r
Exploit, Third Party Advisory exploit
https://github.com/yaowenxiao721/Poc/blob/main/SQLBot/SQLBot-AIModel-Management-Missing-Authorization.md
Release Notes patch
https://github.com/dataease/SQLBot/releases/tag/v1.5.0
Various Sources product
https://github.com/dataease/SQLBot/
Scores
CVSS v3
6.3
EPSS
0.0055
EPSS Percentile
41.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-266
CWE-284
Status
published
Products (1)
fit2cloud/sqlbot
< 1.5.0
Published
Mar 02, 2026
Tracked Since
Mar 02, 2026