Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource
CVE-2026-63307
Description
Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.queryExistent(id, ...) without an ownership check and returns the decrypted password field, allowing any authenticated non-admin user to enumerate datasource IDs and read the plaintext database credentials of datasources owned by other users.
Affected products
2Patches
Vulnerability mechanics
References
3- www.vulncheck.com/advisories/forgecode-arbitrary-code-execution-via-unvetted-mcp-json-in-untrusted-repositorymitrethird-party-advisory
- github.com/OtterMind/Chat2DB/issues/1839mitretechnical-description
- github.com/OtterMind/Chat2DB/releases/tag/v5.3.0mitrerelease-notes
News mentions
0No linked articles in our index yet.