CVE-2026-85689: llmware 0.4.6 SQL Injection via unescaped filter values

Published Sep 4, 2026
·
Updated

llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without parameterization or escaping, in both the SQLite and PostgreSQL backends. The filter validator only checks keys against an allow-list and never sanitizes values. Attacker-controlled filter values reaching the public API via Library.blocklookup and Query.textquerywithcustomfilter / textquerybyauthororspeaker can neutralize the intended filter to disclose rows the caller was scoped out of (cross-document/cross-collection disclosure); on PostgreSQL the flaw permits boolean- and UNION-based SQL injection.

Affected Software

1 affected component
llmware=0.4.6

Event History

Sep 4, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Jul 8, 58646
Event
via NVD·09:19 AM

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

An attacker needs low-privilege access and the ability to supply controlled filter or lookup values through the affected public API paths. No user interaction is required.

2

Which application paths should be prioritized for review?

Review uses of Library.block_lookup, Query.text_query_with_custom_filter, and Query.text_query_by_author_or_speaker where filter or lookup values can originate from an untrusted caller.

3

Does the impact differ between supported database backends?

Yes. The issue can bypass intended row-scoping filters in both SQLite and PostgreSQL, while PostgreSQL is also described as permitting boolean-based and UNION-based SQL injection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203