9.4
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H
Description
CVE-2026-33324 Overview SQLBot, a sophisticated Text-to-SQL system developed by Dataease, is exposed to a prompt injection vulnerability in versions 1.7.0 and earlier. The flaw arises as user-sent queries are integrated directly into the LLM Large...
Basic Information
ID
63B08A12-FC85-512C-99E4-8559CA17CACD
Published
May 6, 2026 at 04:27
Modified
May 6, 2026 at 04:29