SQL injection in DataEase - #VU151952
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in CREATE TABLE DDL generation when importing datasets with attacker-controlled column names. A remote user can upload a crafted Excel or CSV datasource with malicious column names to execute arbitrary code.
The embedded H2 engine must be enabled.