SQL Injection Vulnerability in Anyquery SQL Query Engine by Julien040
CVE-2026-47253

7.3HIGH

Key Information:

Vendor

Julien040

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-47253?

The Anyquery SQL query engine, prior to version 0.4.5, contains a vulnerability that permits low-privileged users to invoke the clear_plugin_cache function, allowing them to manipulate file paths. By using the /v1/query endpoint, attackers can exploit path traversal segments, leading to the recursive deletion of any directory writable by the server process. This poses a significant risk of permanent data loss and contributes to denial of service scenarios, as the affected application can lose access to critical files without revealing sensitive content.

Affected Version(s)

anyquery < 0.4.5

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.