CVE-2026-4530: SQL injection in Aix-DB text2sql agent terminology retriever
A SQL injection flaw (CVE-2026-4530) was disclosed in apconw Aix-DB up to version 1.2.3, affecting the agent/text2sql/rag/terminology_retriever.py component via manipulation of the Description argument. The attack requires local access, a public exploit has been released, and the vendor did not respond to the disclosure.
Disclosed 22 March 2026 · Record updated 13 September 2026
Impact
SQL injection can be triggered through the text2sql RAG terminology retriever; exploit code is publicly available, though exploitation requires local access.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-4530
