SQL Chat contains four unauthenticated API endpoints that...
Critical severity
Unreviewed
Published
Sep 5, 2026
to the GitHub Advisory Database
•
Updated Sep 5, 2026
Description
Published by the National Vulnerability Database
Sep 5, 2026
Published to the GitHub Advisory Database
Sep 5, 2026
Last updated
Sep 5, 2026
SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.
References