HighVulnerability
GHSA-mwwr-p57h-56pf: @bytebase/dbhub's read-only mode does not prevent database writes
- Identifiers
- CVE-2026-61788GHSA-mwwr-p57h-56pf
- Published
- Record updated
- Affected
- @bytebase/dbhub < 0.22.6
- Fixed in
- 0.22.6
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
@bytebase/dbhub's `readonly = true` setting on the `execute_sql` tool does not make connections read-only. The PostgreSQL and SQLite connectors only apply database-level read-only mode when `config.readonly` is set, but `source.readonly` can never be populated, so that path never runs. Enforcement falls to a classifier that checks only each statement's leading keyword, so a `SELECT` calling functions such as `setval`, `lo_export`, `pg_read_file` or `dblink_exec` can write data, read or write server files, or execute commands. The HTTP transport is unauthenticated and binds to `0.0.0.0` by default.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading