CVE-2026-33324: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided q...
Added to the CISA Known Exploited Vulnerabilities catalog on 05 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and th...
Required action: Review and patch if applicable to your AI infrastructure.