🚨 CVE-2026-86123
SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.
🎖@cveNotify

GitHub
GitHub - sqlchat/sqlchat: Chat-based SQL Client and Editor for the next decade
Chat-based SQL Client and Editor for the next decade - sqlchat/sqlchat
September 5, 2026 37