📅 Showing Year: 2026
(January 1 - December 31, 2026)
View All Years →
Showing 21 - 21
of 21 CVEs
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a remote unauthenticated attacker to upload arbitrary Excel/CSV files and inject data di...