SQL Vulnerability in Anyquery Affects SQLite Users
CVE-2025-61679

7.7HIGH

Key Information:

Vendor

Julien040

Status
Vendor
CVE Published:
3 October 2025

What is CVE-2025-61679?

A vulnerability in Anyquery, an SQL query engine that sits atop SQLite, has been identified in versions 0.4.3 and earlier. This flaw permits unauthorized individuals with local access to exploit the HTTP server, exposing private integration data such as emails. Notably, this access occurs without any alerts regarding a foreign login, leaving sensitive information vulnerable. The issue has been resolved in version 0.4.4.

Affected Version(s)

anyquery < 0.4.4

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61679 : SQL Vulnerability in Anyquery Affects SQLite Users