VYPR

Anyquery

by Julien040

Source repositories

CVEs (6)

  • CVE-2026-47252CriSep 17, 2026
    risk 0.52cvss 9.0epss 0.01

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a…

  • CVE-2026-50006CriSep 14, 2026
    risk 0.52cvss 9.1epss 0.01

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the…

  • CVE-2025-61679HigOct 3, 2025
    risk 0.50cvss 7.7epss 0.00

    Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even with low privileges, to use the http server through the port unauthenticated, and access private integration data like emails,…

  • CVE-2026-54628HigSep 14, 2026
    risk 0.49cvss 8.6epss 0.01

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A…

  • CVE-2026-54629HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A…

  • CVE-2026-47253HigSep 14, 2026
    risk 0.40cvss 7.3epss 0.00

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A…