SQL Injection Vulnerability in zhongyu09 OpenChatBI Software
CVE-2026-84061
5.3MEDIUM
What is CVE-2026-84061?
A security flaw has been identified in the zhongyu09 OpenChatBI software, specifically in the function _validate_sql_safety located in the file openchatbi/text2sql/generate_sql.py. This vulnerability allows attackers to perform SQL injection attacks remotely. Earlier versions from v0.2.0 to v0.2.2 lack any form of SQL safety validation, while version v0.3.0 introduced a validator that has been deemed incomplete. The upcoming v1.0.0b1/main retains this insufficient validation with an optional stricter mode. Despite early disclosure to the vendor, there has been no response regarding this issue.
Affected Version(s)
OpenChatBI 0.1
OpenChatBI 0.2
OpenChatBI 0.3.0
