CVE-2026-61852 | Chartbrew up to 5.2.1 SQL Query Execution runQuery.js runQuery row_limit sql injection

SecurityVulns

A vulnerability described as critical has been identified in Chartbrew up to 5.2.1. Affected is the function runQuery of the file server/modules/ai/orchestrator/tools/runQuery.js of the component SQL Query Execution. Such manipulation of the argument row_limit leads to sql injection.

This vulnerability is listed as CVE-2026-61852. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More