CVE-2025-15597Disclosure(fit2cloud / sqlbot)

LOWCVSS 6.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.0 mitigates this issue. The name of the patch is d640ac31d1ce64ce90e06cf7081163915c9fc28c. Upgrading the affected component is recommended. Multiple endpoints are affected. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sqlbot

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
sqlbot

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-02: 4Technical Details · 2026-03-02: 203-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15597 - Dataease SQLBot API Endpoint http://assistant.py access control Intel Report: https://ift.tt/ynmLbhX

    Post summary

    An alert for CVE-2025-15597 highlights an access control flaw on Dataease’s SQLBot API endpoint; no PoC, exploit, active use, patch, or debunking information is provided.

    0000076
    342 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15597 Unauthenticated Remote Access Control Bypass in Dataease SQLBot 1.4.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15597

    Post summary

    A new unauthenticated remote access control bypass vulnerability (CVE-2025-15597) has been disclosed for Dataease SQLBot 1.4.0.

    0000074
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-15597 A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API … https://www.cve.org/CVERecord?id=CVE-2025-15597 ----- Traducción: CVE-2025-15597 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2025-15597, was identified in Dataease SQLBot up to version 1.4.0, affecting an unknown function in assistant.py, with no further details on exploitation or patches provided.

    0000073
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15597 A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API … https://www.cve.org/CVERecord?id=CVE-2025-15597

    Post summary

    A vulnerability was identified in Dataease SQLBot up to version 1.4.0, affecting an unknown function in assistant.py, but no further details or mitigations are provided.

    00000370
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfit2cloudsqlbot---

Explore more