sqlchat vulnerability

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.

Published 5 Sep 2026Updated 5 Sep 20265 sources
CVSS 9.4

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.