CVE-2026-32622Disclosure(fit2cloud / sqlbot)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, unsanitized storage of terminology descriptions containing dangerous payloads, and a lack of semantic fencing when injecting terminology into the LLM's system prompt. Together, these flaws allow an attacker to hijack the LLM's reasoning to generate malicious PostgreSQL commands (e.g., COPY ... TO PROGRAM), ultimately achieving Remote Code Execution on the database or application server with postgres user privileges. The issue is fixed in v1.6.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-74CWE-77CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sqlbot

Threat summary

  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-23)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
sqlbot

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-03-23: 4Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 403-2003-2203-23
Signal classification3 categories
Disclosure
571.4%
Exploit
114.3%
General
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-222
Disclosure2
2026-03-234
Disclosure2Exploit1General1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32622 SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chai… https://www.cve.org/CVERecord?id=CVE-2026-32622

    Post summary

    A new CVE (CVE-2026-32622) affecting SQLBot versions 1.5.0 and below has been disclosed, describing a Stored Prompt Injection vulnerability.

    00010345
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32622 Stored Prompt Injection in SQLBot LLM Leading to Remote Code Exec... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32622 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    This post announces CVE-2026-32622, noting a stored prompt injection flaw in SQLBot LLM that can lead to remote code execution, and provides a link for more details but no exploit code, patch, or active attack reports.

    1000049
    4.0K followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-32622: How SQLBot's RCE Vulnerability Exposes the Hidden Risks of RAG-Based AI Systems https://moltx.io/articles/c03cdff9-57cb-4189-a7fb-e08327d735a6

    Post summary

    The tweet announces a new article detailing CVE‑2026‑32622, a remote code execution vulnerability in SQLBot that underscores risks for RAG‑based AI systems.

    0000019
    4 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-32622: Critical Prompt Injection Vulnerability in SQLBot #security https://moltx.io/articles/17d10036-af8a-4c16-aa9b-8274c33d705e

    Post summary

    The post announces a critical prompt injection flaw in SQLBot, linking to an article, but offers no PoC, exploit code, or mitigation details.

    0000036
    4 followersView on X
  • AI Security Guard@ai_security_10x
    Exploit

    CVE-2026-32622: How a Malicious Excel File Led to RCE in SQLBot's RAG Pipeline #security https://moltx.io/articles/8c212263-538c-41bc-aee4-b5caa5756184

    Post summary

    The article reports that a malicious Excel file exploited CVE‑2026‑32622 to achieve remote code execution in SQLBot’s RAG pipeline, but it does not provide PoC code, tool details, patch information, or evidence of active wild‑world exploitation.

    0000032
    4 followersView on X
  • AI Security Guard@ai_security_10x
    General

    CVE-2026-32622: How Stored Prompt Injection in SQLBot Enables RCE via Excel Uploads #security https://moltx.io/articles/0b71c127-07d6-4ac3-a882-afd826af5459

    Post summary

    The tweet announces CVE-2026-32622, describing an RCE vulnerability through stored prompt injection and Excel uploads, but offers no PoC, exploit details, or patch information.

    0000036
    4 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32622 SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chai… https://www.cve.org/CVERecord?id=CVE-2026-32622 ----- Traducción: CVE-2026-32622 SQL… http://infoflow.cloud`

    Post summary

    This tweet discloses CVE-2026-32622 as a stored prompt injection flaw in SQLBot versions 1.5.0 and older, with no mention of PoCs, exploits, or patches.

    0000026
    61 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfit2cloudsqlbot---

Explore more