SQL injection in Chatwoot - CVE-2025-21628
Published: January 9, 2025 / Updated: May 5, 2026
Chatwoot
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in conversation and contact filters endpoints when processing the query_operator parameter from frontend or API requests. A remote user can send a specially crafted request with a tautological WHERE clause to execute arbitrary SQL commands.