Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49360— Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB

Quick assessment

Affected
DataRecce recce
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Recce 是一个用于增强 dbt(data build tool)拉取请求(PR)审查的数据验证工具包。在版本 1.50.0 之前,若 OSS(开源服务器)部署未启用身份验证,并将服务器暴露给不受信任的网络,则通过查询运行 API(query run API)可发起未认证的 SQL 执行攻击。当 Recce 配置为使用 DuckDB 后端的项目时,攻击者可利用 DuckDB 的文件系统原语,读取和写入 Recce 服务器进程有权访问的文件。 该漏洞的影响程度取决于 Recce 的具体部署方式,可能包括:本地文件泄

CVSS 7.8 · High EPSS 0.45% · P38

Affected Version Matrix 1

VendorProduct Version RangeStatus
DataRecce recce < 1.50.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49360

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB
Source: CVE Program / CVE List V5
Vulnerability Description
Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL execution through the query run API. When Recce is configured with a DuckDB-backed project, an attacker can use DuckDB filesystem primitives to read and write files accessible to the Recce server process. The impact depends on how Recce is deployed, but may include disclosure of local files, tampering with Recce/dbt artifacts, modification of browser-served static files leading to stored XSS, and modification of application files if those paths are writable. If Recce is run as root, file access occurs with root privileges inside that host or container. This issue has been patched in Recce `v1.50.0`. Users should upgrade to Recce `v1.50.0` or later. The patch restricts unsafe file read/write behavior for DuckDB-backed query execution and hardens the affected query path. Other warehouse adapters have also been reviewed for similar exposure. Users who cannot upgrade immediately should avoid exposing `recce server` to the public internet or any untrusted network. Recommended mitigations include enabling authentication or placing Recce behind an authenticated reverse proxy/VPN, running Recce as a non-root user, using a read-only application filesystem where possible, and ensuring that sensitive files or credentials are not available to the Recce process.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
DataRecce recce < 1.50.0 -

II. Public POCs for CVE-2026-49360

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7156 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-49360

登录查看更多情报信息。

Vendor Advisories for CVE-2026-49360 (2)

Vendor Pages for CVE-2026-49360 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49360

No comments yet


Leave a comment