Second-Order SQL Injection in SQLBot Affects PostgreSQL Management
CVE-2026-53557
7.7HIGH
What is CVE-2026-53557?
SQLBot, an intelligent Text-to-SQL system, has a vulnerability where an authenticated user can exploit the system by submitting a malicious value in the datasource configuration. This crafted input can lead to a second-order SQL injection when the datasource is removed, allowing the execution of arbitrary operating-system commands with elevated privileges in the SQLBot container. This issue has been addressed in version 1.9.0 of SQLBot.
Affected Version(s)
SQLBot < 1.9.0
