PT-2026-3859 · Pandas+2 · Pandas+2

CVE-2025-69285

·

Publicado

2026-01-21

·

Atualizado

2026-02-02

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SQLBot versions prior to 1.5.0
Description SQLBot is an intelligent data query system based on a large language model and RAG. A missing authentication check in the /api/v1/datasource/uploadExcel endpoint allows unauthenticated remote attackers to upload arbitrary Excel or CSV files and inject data directly into the PostgreSQL database. The endpoint bypasses token validation due to being explicitly whitelisted. Uploaded files are parsed using pandas and inserted into the database via the to sql() function with the if exists='replace' option.
Recommendations Update to version 1.5.0 or later.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69285
GHSA-CRFM-CCH4-HJPV

Produtos afetados

Postgresql
Sqlbot
Pandas