SQLBot 是一个基于大语言模型和 RAG 的智能 Text-to-SQL 系统。在 1.9.0 版本之前,经过身份验证的上传者可以通过 端点提交 image/svg+xml 格式的助手 UI 标志。SQLBot 在存储该 SVG 文件时,未对其中嵌入的活跃内容(如内嵌 JavaScript)进行清理或校验。随后,SQLBot 通过 从同一应用源内联提供该文件。当其他用户加载该生成的资源时,SVG 中嵌入的 JavaScript 会在 SQLBot Web 应用的上下文中执行,从而导致存储型跨站脚本攻击(Stor
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53557 | 7.7 HIGH | SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Executio |
| CVE-2026-53554 | 7.3 HIGH | SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Impo |
| CVE-2026-53556 | 6.0 MEDIUM | SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read |
No comments yet