CVE-2026-33324: SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided q...

Added to the CISA Known Exploited Vulnerabilities catalog on 05 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and th...

Required action: Review and patch if applicable to your AI infrastructure.