Sploitus

CVE-2025-69285

No indexed exploits for CVE-2025-69285 yet

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a remote unauthenticated attacker to upload arbitrary Excel/CSV files and inject data directly into the PostgreSQL database. The endpoint is explicitly added to the authentication whitelist, causing the TokenMiddleware to bypass all token validation. Uploaded files are parsed by pandas and inserted into the database via to_sql() with if_exists='replace' mode. The vulnerability has been fixed in v1.5.0. No known workarounds are available.

Affected products
Postgresql, Sqlbot, Pandas
fit2cloud Sqlbot
< 1.5.0
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
6.1 MEDIUM
EPSS
0.4% (32th percentile)
Weakness
CWE-306
NVD status
Analyzed
Published
2026-01-21
CVE-2025-69285 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-69285 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-69285 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.