CVE-2026-53555: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl
Summary
SQLBot, a system that converts natural language questions into database queries using AI and external data retrieval, had a security flaw before version 1.9.0 where authenticated users could upload SVG image files with embedded malicious code. When other users viewed these images, the malicious code would run in their browser session, potentially allowing attackers to steal data or perform actions on behalf of victims (this vulnerability is called stored cross-site scripting, where harmful code is saved and executed later).
Solution / Mitigation
This issue is fixed in version 1.9.0.
Vulnerability Details
EPSS: 0.0%
September 17, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-53555
First tracked: September 17, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 85%