CVE-2026-33324
SQLBot versions 1.7.0 and earlier contain a prompt injection flaw in the Text2SQL chat interface. An authenticated attacker can inject a malicious question that causes the LLM to generate and execute arbitrary SQL, which when using a PostgreSQL backend can lead to remote code execution via COPY FROM PROGRAM. The issue is resolved in version 1.7.1.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
fit2cloud sqlbot (versions ≤1.7.0)
Real-world impact
An authenticated attacker could run arbitrary commands on the host system, potentially leading to full compromise of the server.
Why this severity
CVSS v4.0 base score 9.4 (Critical) reflects network‑adjacent attack, low complexity, low privileges, no user interaction, and high impacts to confidentiality, integrity, availability, and subsequent system impacts.
What to do about it
- 011. Upgrade SQLBot to version 1.7.1 or later.
- 022. Verify the upgrade by checking the version number or release notes.
- 033. Restart the SQLBot service if required by the upgrade process.
NVD description (fix mentioned in version 1.7.1)
Timeline
- May 5, 2026 · May 5, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/dataease/SQLBot/security/ad…exploitvendor advisory