SQLBot stored prompt injection chain enables RCE (CVE-2026-32622)
SQLBot versions 1.5.0 and below contain a stored prompt injection vulnerability chaining a missing permission check on the Excel upload API, unsanitized terminology storage, and no semantic fencing of terminology injected into the LLM system prompt. An authenticated attacker could hijack the LLM's reasoning to emit malicious PostgreSQL commands such as COPY ... TO PROGRAM, achieving remote code execution with postgres privileges; fixed in v1.6.0.
Disclosed 19 March 2026 · Record updated 13 September 2026
Impact
Any authenticated user could achieve remote code execution on the database or application server with postgres user privileges via injected terminology payloads.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-32622
