SQL Injection Vulnerability in Baserow 2.3.3 by Baserow
CVE-2026-19754
8.6HIGH
What is CVE-2026-19754?
Baserow 2.3.3 has a SQL injection vulnerability found within the index() formula function. This flaw allows low-privileged authenticated users to inject malicious SQL code by providing an undocumented fourth argument. This argument is parsed as a SQL template and executed directly within PostgreSQL, using the database connection privileges of the Baserow PostgreSQL role, rather than those of the authenticated user. Consequently, this vulnerability can lead to unauthorized data access and manipulation within the Baserow application.
Affected Version(s)
Baserow Windows 2.3.3
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Miguel GĂłmez
Fluid Attacks' AI SAST Scanner
