CVE-2026-7023: ByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection
A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/databaseimpl.go of the component databaseTool. Performing a manipulation results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7023?
CVE-2026-7023 is classified as a high severity SQL injection vulnerability affecting ByteDance coze-studio version up to 0.5.1.
How do I fix CVE-2026-7023?
To fix CVE-2026-7023, update ByteDance coze-studio to the latest version that addresses the SQL injection vulnerability.
What kind of vulnerability is CVE-2026-7023?
CVE-2026-7023 is an SQL injection vulnerability that can allow an attacker to execute arbitrary SQL code.
Which component is affected by CVE-2026-7023?
CVE-2026-7023 affects the ExecuteSQL function in the backend/domain/memory/database/service/database_impl.go file of the databaseTool component.
What versions of ByteDance coze-studio are vulnerable to CVE-2026-7023?
Versions of ByteDance coze-studio up to and including 0.5.1 are vulnerable to CVE-2026-7023.