PT-2025-40603 · Anyquery · Anyquery

Keremergur

·

Published

2025-10-03

·

Updated

2025-10-04

·

CVE-2025-61679

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Anyquery versions 0.4.3 and below
Description Anyquery is an SQL query engine built on top of SQLite. Attackers who have gained access to localhost, even with low privileges, can use the http server through the port unauthenticated and access private integration data, such as emails, without any warning of a foreign login from the provider. The issue affects versions running prior to 0.4.4.
Recommendations Update to version 0.4.4 or later.

Exploit

Fix

Improper Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-61679
GHSA-5F7P-RHMQ-HVC7

Affected Products

Anyquery