Stored Cross-Site Scripting Vulnerability in SQLBot by Dataease
CVE-2026-53555
5.1MEDIUM
What is CVE-2026-53555?
An authenticated user in SQLBot prior to version 1.9.0 can upload an SVG logo through the PATCH /api/v1/system/assistant/ui endpoint without proper sanitization. This vulnerability allows malicious JavaScript embedded in the uploaded SVG to execute when other users access the generated resource. As a result, attackers can exploit the application's context, gaining unauthorized access to the victim's session data and performing actions on behalf of the victim. This security flaw was mitigated in version 1.9.0.
Affected Version(s)
SQLBot < 1.9.0
