CVE-2026-33324Disclosure(fit2cloud / sqlbot)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the SQL extracted from the LLM response is executed against the database without validation or sanitization. An authenticated attacker can craft a malicious question to manipulate the LLM into generating and executing arbitrary SQL statements. When connected to a PostgreSQL data source, this can lead to remote code execution via COPY FROM PROGRAM. This issue has been fixed in version 1.7.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sqlbot

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
sqlbot

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 105-0505-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33324 Prompt Injection and SQL Injection in SQLBot 1.7.0 Leading to Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33324

    Post summary

    The snippet announces CVE-2026-33324, detailing prompt injection and SQL injection flaws in SQLBot 1.7.0 that enable remote code execution, but does not provide a PoC, exploit code, or remediation guidance.

    0000037
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33324 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt… https://www.cve.org/CVERecord?id=CVE-2026-33324 ----- Traducción: CVE-2026-33324 SQL… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-33324, highlighting a prompt injection flaw in SQLBot’s Text2SQL interface for versions up to 1.7.0, and links to the official CVE record.

    0000033
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33324 SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt… https://www.cve.org/CVERecord?id=CVE-2026-33324

    Post summary

    The tweet announces CVE-2026-33324, stating that SQLBot’s Text2SQL chat interface (v1.7.0 and earlier) is vulnerable to a prompt injection flaw. No PoC, exploit code, patch, or active exploitation information is provided.

    00000158
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfit2cloudsqlbot---

Explore more