CVE-2026-84061: zhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injection

Published Sep 1, 2026
·
Updated

A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function validatesqlsafety of the file openchatbi/text2sql/generatesql.py. Performing a manipulation results in sql injection. The attack can be initiated remotely. Versions v0.2.0 through v0.2.2 have no SQL safety validation at all, while v0.3.0 introduced a validator and v1.0.0b1/main kept the same incomplete one with an optional stricter mode. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
zhongyu09 OpenChatBI<=0.3.0, >=0.2.0<=0.2.2, >=0.3.0<=0.3.0, >=1.0.0b1<=main

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade zhongyu09 OpenChatBI to a version that resolves this vulnerability.

    Fixed in 0.3.0
  2. Upgrade

    Upgrade zhongyu09 OpenChatBI to a version that resolves this vulnerability.

    Fixed in 1.0.0b1
  3. Configuration

    Enable the optional stricter mode in _validate_sql_safety (introduced/available in v1.0.0b1/main) to strengthen SQL injection protection.

    zhongyu09 OpenChatBI - openchatbi/text2sql/generate_sql.py (_validate_sql_safety) stricter mode for SQL safety validation = enabled

Event History

Sep 1, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need?

The attack can be initiated remotely and requires low privileges. No user interaction is required.

2

Are deployments running versions with SQL safety validation protected?

No. Version 0.3.0 introduced SQL safety validation, but the validator is described as incomplete; v1.0.0b1 and the main branch retained the same incomplete validator. An optional stricter mode exists in v1.0.0b1/main, but the available information does not establish that it fully mitigates the issue.

3

Which versions should be considered exposed?

Versions v0.2.0 through v0.2.2 have no SQL safety validation at all. The issue is reported in OpenChatBI up to 0.3.0, with the same incomplete validation also noted in v1.0.0b1 and main.

4

Is a vendor fix or workaround documented?

No vendor fix or workaround is provided in the available information. The vendor was contacted about the disclosure but did not respond.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203