CVE-2026-54629
Last modified
CVE-2026-54629 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions.
Description
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE VIRTUAL TABLE statements to provide a local path to these modules, which use hashicorp/go-getter under the Anyquery server process and return the selected file contents as queryable table rows. The disclosure is limited only by the filesystem permissions of the server process and can expose system configuration, credentials, and private keys. This issue is fixed in version 0.4.5.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| julien040 | anyquery | < 0.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-54629?
How severe is CVE-2026-54629?
How do I fix CVE-2026-54629?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54623django CMS is an easy-to-use and developer-friendly enterpri…7.1
- CVE-2026-54624django CMS is an easy-to-use and developer-friendly enterpri…6.5
- CVE-2026-54625django CMS is a content management system powered by Django.…4.8
- CVE-2026-54626SAIL is a cross-platform library for loading and saving imag…9.8
- CVE-2026-54627SAIL is a cross-platform library for loading and saving imag…9.8
- CVE-2026-54628Anyquery is an SQL query engine built on top of SQLite. Prio…8.6
- CVE-2026-5463Command injection vulnerability in console.run_module_with_o…9.8
- CVE-2026-54632SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NE…7.5
- CVE-2026-54633PoDoFo is a C++17 PDF manipulation library. From version 1.0…6.9
- CVE-2026-54634Hamlib is a ham radio control library for radios, rotators, …7.3
- CVE-2026-54635pytonapi is a Python SDK for TONAPI that provides REST API, …7.5
- CVE-2026-54636Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron pl…9.9
Are you affected by CVE-2026-54629?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
