{"data":{"id":"6d08121e-e132-427c-9243-dfd4ef826455","title":"GHSA-mwwr-p57h-56pf: @bytebase/dbhub's read-only mode does not prevent database writes","summary":"@bytebase/dbhub's `readonly = true` setting on the `execute_sql` tool does not make connections read-only. The PostgreSQL and SQLite connectors only apply database-level read-only mode when `config.readonly` is set, but `source.readonly` can never be populated, so that path never runs. Enforcement falls to a classifier that checks only each statement's leading keyword, so a `SELECT` calling functions such as `setval`, `lo_export`, `pg_read_file` or `dblink_exec` can write data, read or write server files, or execute commands. The HTTP transport is unauthenticated and binds to `0.0.0.0` by default.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://github.com/advisories/GHSA-mwwr-p57h-56pf","publishedAt":"2026-09-24T19:37:59.000Z","cveId":"CVE-2026-61788","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["@bytebase/dbhub@< 0.22.6 (fixed: 0.22.6)"],"affectedPackageNames":["@bytebase/dbhub"],"affectedPackageRefs":["npm:@bytebase/dbhub"],"affectedVendors":[],"affectedVendorsRaw":["@bytebase/dbhub"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00303,"epssCheckedAt":"2026-10-10T06:41:59.205Z","kevDateAdded":null,"advisoryAliases":["GHSA-mwwr-p57h-56pf"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-09-24T19:37:59.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}