CVE-2026-65980 | Chartbrew up to 5.2.2 ClickHouse protocol clickhouse.protocol.js applySqlVariables sql injection

SecurityVulns

A vulnerability labeled as critical has been found in Chartbrew up to 5.2.2. Affected by this vulnerability is the function applySqlVariables of the file server/sources/plugins/clickhouse/clickhouse.protocol.js of the component ClickHouse protocol. Such manipulation leads to sql injection.

This vulnerability is referenced as CVE-2026-65980. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.VulDB Recent EntriesRead More