CVE-2026-32950: SQLBot: RCE via SQL Injection in Excel Upload Endpoint
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user (even the lowest-privileged) to fully compromise the backend server. The root cause is twofold: Excel Sheet names are concatenated directly into PostgreSQL table names without sanitization (datasource.py#L351), and those table names are embedded into COPY SQL statements via f-strings instead of parameterized queries (datasource.py#L385-L388). An attacker can bypass the 31-character Sheet name limit using a two-stage technique—first uploading a normal file whose data rows contain shell commands, then uploading an XML-tampered file whose Sheet name injects a TO PROGRAM 'sh' clause into the SQL. Confirmed impacts include arbitrary command execution as the postgres user (uid=999), sensitive file exfiltration (e.g., /etc/passwd, /etc/shadow), and complete PostgreSQL database takeover. This issue has been fixed in version 1.7.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32950?
CVE-2026-32950 has been classified as a critical vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2026-32950?
To fix CVE-2026-32950, upgrade your SQLBot installation to version 1.7.0 or later.
Which versions are affected by CVE-2026-32950?
CVE-2026-32950 affects SQLBot versions prior to 1.7.0.
What is the exploit vector for CVE-2026-32950?
The exploit vector for CVE-2026-32950 is through an SQL Injection in the /api/v1/datasource/uploadExcel endpoint.
What kind of attack is possible with CVE-2026-32950?
CVE-2026-32950 enables attackers to perform Remote Code Execution (RCE) on vulnerable SQLBot installations.