{"data":{"id":"c791eb33-2c63-4b6f-9e44-1e749dfa4d66","title":"CVE-2026-53556: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat","summary":"SQLBot is a system that converts natural language questions into SQL database queries using AI and RAG (retrieval-augmented generation, where external data sources help the AI answer questions). Before version 1.9.0, the system failed to safely handle user-supplied table names when building SQL queries, allowing authenticated attackers to use special PostgreSQL functions to read sensitive files like /etc/passwd (which contains user account information) and configuration files, potentially exposing secrets and source code.","solution":"Update to version 1.9.0 or later. According to the source, 'This issue is fixed in version 1.9.0.'","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53556","publishedAt":"2026-09-17T22:17:00.073Z","cveId":"CVE-2026-53556","cweIds":["CWE-89"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["SQLBot"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-17T22:17:00.073Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}