CVE-2025-15598Disclosure(fit2cloud / sqlbot)

LOWCVSS 5.9 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made public and could be used. A comment in the source code warns users about using this feature. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sqlbot

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
sqlbot

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-03: 4Technical Details · 2026-03-03: 103-03
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets5 URLs
Full discourse4 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15598 Intel Report: https://ift.tt/mFtaeLZ

    Post summary

    The alert references CVE-2025-15598 and links to an Intel Report, but provides no additional technical or exploit information.

    0000066
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-15598 A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the compone… https://www.cve.org/CVERecord?id=CVE-2025-15598 ----- Traducción: CVE-2025-15598 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2025-15598, was identified in Dataease SQLBot up to version 1.5.1, affecting the validateEmbedded function in the auth middleware. No PoC, exploit, or patch details were provided.

    0000058
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15598 A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the compone… https://www.cve.org/CVERecord?id=CVE-2025-15598

    Post summary

    A vulnerability in Dataease SQLBot up to version 1.5.1 affecting the validateEmbedded function was disclosed, with technical details provided but no PoC, exploit, or patch information.

    00000297
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15598 - Dataease SQLBot JWT Token http://auth.py validateEmbedded signature verification Intel Report: https://ift.tt/JmbVKIx

    Post summary

    The post alerts to CVE-2025-15598 with a brief mention of Dataease and JWT token validation, provides a link to an Intel report, but offers no proof of concept, exploit details, patch information, or active exploitation claims.

    0000058
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfit2cloudsqlbot---

Explore more