Server-Side Request Forgery Vulnerability in SQLBot by DataEase
CVE-2026-32949
What is CVE-2026-32949?
SQLBot, an advanced data query system, is prone to a Server-Side Request Forgery vulnerability in versions before 1.7.0. This issue allows attackers to exploit the /api/v1/datasource/check endpoint by introducing a malicious parameter to a forged MySQL data source. During the verification process, an attacker-controlled MySQL server can send a harmful LOAD DATA LOCAL INFILE command. This command tricks the SQLBot backend into reading sensitive local files, such as configuration files and system data, and then sending those contents back to the attacker, potentially exposing critical information and compromising server security. This vulnerability was addressed in version 1.7.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SQLBot < 1.7.0
