PT-2025-40603 · Anyquery · Anyquery
Keremergur
·
Published
2025-10-03
·
Updated
2025-10-04
·
CVE-2025-61679
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Anyquery versions 0.4.3 and below
Description
Anyquery is an SQL query engine built on top of SQLite. Attackers who have gained access to localhost, even with low privileges, can use the http server through the port unauthenticated and access private integration data, such as emails, without any warning of a foreign login from the provider. The issue affects versions running prior to 0.4.4.
Recommendations
Update to version 0.4.4 or later.
Exploit
Fix
Improper Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anyquery