SQL Injection Vulnerability in zhongyu09 OpenChatBI Software
CVE-2026-84061

5.3MEDIUM

Key Information:

Vendor

Zhongyu09

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84061?

A security flaw has been identified in the zhongyu09 OpenChatBI software, specifically in the function _validate_sql_safety located in the file openchatbi/text2sql/generate_sql.py. This vulnerability allows attackers to perform SQL injection attacks remotely. Earlier versions from v0.2.0 to v0.2.2 lack any form of SQL safety validation, while version v0.3.0 introduced a validator that has been deemed incomplete. The upcoming v1.0.0b1/main retains this insufficient validation with an optional stricter mode. Despite early disclosure to the vendor, there has been no response regarding this issue.

Affected Version(s)

OpenChatBI 0.1

OpenChatBI 0.2

OpenChatBI 0.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yogender (VulDB User)
VulDB CNA Team
.