PT-2026-30453 · Zhongyu09 · Openchatbi

Goku

·

Published

2026-04-05

·

Updated

2026-05-20

·

CVE-2026-5586

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zongyu09 openchatbi versions up to 0.2.1
Description A flaw exists in the Multi-stage Text2SQL Workflow component of zhongyu09 openchatbi. Manipulation of the keywords argument can result in SQL injection. This issue can be exploited remotely. The vulnerability has been publicly disclosed.
Recommendations Versions prior to 0.2.1 should be updated.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5586

Affected Products

Openchatbi