Vulnerability  ·  2026-09-19

ArcadeDB / CordysCRM / SQLBot cluster — lower-severity SQL injection and stored XSS in AI-adjacent admin functions

VulnerabilityMedium impactGlobalCVE-2026-53556
SQLBot's data-preview endpoint is vulnerable to SQL injection via an unsanitized table name parameter.
Continues the pattern of unsafe SQL construction across SQLBot's datasource-handling endpoints in this LLM/RAG-based query tool.
The POST /api/v1/datasource/previewData endpoint incorporates a client-controlled table_name value into generated SQL without safe identifier handling.
SQLBot < 1.9.0
Upgrade to SQLBot 1.9.0 or later.
GitHub commit (fix)NVD CVE-2026-53556
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →