TROYANOSYVIRUS
Back to CVEs

CVE-2025-69285

MEDIUM
6.1

Description

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a remote unauthenticated attacker to upload arbitrary Excel/CSV files and inject data directly into the PostgreSQL database. The endpoint is explicitly added to the authentication whitelist, causing the TokenMiddleware to bypass all token validation. Uploaded files are parsed by pandas and inserted into the database via to_sql() with if_exists='replace' mode. The vulnerability has been fixed in v1.5.0. No known workarounds are available.

CVE Details

CVSS v3.1 Score6.1
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published1/21/2026
Last Modified2/2/2026
Sourcenvd
Honeypot Sightings0

Affected Products

fit2cloud:sqlbot

Weaknesses (CWE)

CWE-306

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.