Beveiligingsadvies

CVE-2026-61461

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-10 18:10:35
Laatst bijgewerkt 2026-07-14 22:03:38
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database.