Anyquery 是构建在 SQLite 之上的 SQL 查询引擎。在 0.4.5 版本之前, 中的 SQL 标量函数在未过滤路径穿越片段(如 )的情况下,将调用方可控制的 参数直接传入 ,并随后使用 执行删除操作。持有低权限 bearer-token 的用户可通过 HTTP 端点调用该函数,导致 解析 片段后,路径会跳出 目录,而 会递归删除 Anyquery 服务器进程可写的任意可达目录。该漏洞会导致永久性数据丢失和服务中断,但不会泄露文件内容。此问题已在 0.4.5 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50006 | 9.1 CRITICAL | Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via U |
| CVE-2026-54628 | 8.6 HIGH | Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules |
| CVE-2026-54629 | 7.5 HIGH | Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mo |
No comments yet