CVE-2026-45535

Source
https://cve.org/CVERecord?id=CVE-2026-45535
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45535.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45535
Aliases
  • GHSA-pv23-p64m-4pxf
Published
2026-07-15T19:39:47.951Z
Modified
2026-08-12T16:24:38.922635Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
DataEase: Stored SQL Injection Vulnerability
Details

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} and SqlparserUtils.handleVariableDefaultValue() inserts them with String.replace() without escaping or parameterization, causing stored SQL injection whenever a user with dataset read permission accesses the dataset. This issue is fixed in version 2.10.23.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45535.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/dataease/dataease

Affected ranges

Type
GIT
Repo
https://github.com/dataease/dataease
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.10.23"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v2.*
v2.10.0
v2.10.1
v2.10.10
v2.10.11
v2.10.12
v2.10.13
v2.10.14
v2.10.15
v2.10.16
v2.10.17
v2.10.18
v2.10.19
v2.10.2
v2.10.20
v2.10.21
v2.10.22
v2.10.3
v2.10.4
v2.10.5
v2.10.6
v2.10.7
v2.10.8
v2.10.9
v2.2.0
v2.3.0
v2.6.0

Database specific

vanir_signatures_modified
"2026-08-12T16:24:38Z"
vanir_signatures
[
    {
        "id": "CVE-2026-45535-0fae2ff0",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 4601.0,
            "function_hash": "145806032203346986228141870424549737423"
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "function": "handleVariableDefaultValueWithPreparedParams",
            "file": "core/core-backend/src/main/java/io/dataease/commons/utils/DeSqlparserUtils.java"
        }
    },
    {
        "id": "CVE-2026-45535-24e6a6e0",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 3665.0,
            "function_hash": "297120888404016560054635098541197546842"
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "function": "handleVariableDefaultValueWithPreparedParams",
            "file": "core/core-backend/src/main/java/io/dataease/commons/utils/SqlparserUtils.java"
        }
    },
    {
        "id": "CVE-2026-45535-96c1617e",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "118196236560150462429540963242073320606",
                "115270960358011268433505828068930713313",
                "326257906427392963341240931420471592685",
                "242646130002341030608844711918049013086",
                "235635682715367136681181383768876071823",
                "40414585612220223607230879411039324233",
                "158451763707895779637296866078935499482",
                "210777076313855608479828386858194926901",
                "219924542140767621952722843260803247663",
                "161055803918564106332134621881248663637",
                "247783534813435479365210526411409223820",
                "184596499212626809073204367704191420388"
            ]
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/dataset/manage/DatasetDataManage.java"
        }
    },
    {
        "id": "CVE-2026-45535-9964427a",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 4246.0,
            "function_hash": "300773633739470513794147496039477694274"
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "function": "getTableFields",
            "file": "core/core-backend/src/main/java/io/dataease/dataset/manage/DatasetDataManage.java"
        }
    },
    {
        "id": "CVE-2026-45535-a40d514c",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "11401329150859328278953775016222556499",
                "314048420593121333027132047399845481865",
                "185734621979970478954334934089240518637",
                "235340033112916777389217289652768156743",
                "232334512980923841940585559052701885734",
                "185346904935901331568875182906574239908",
                "48311262042734491295919655308076174612",
                "339200018490040596015568645681713966705",
                "235340033112916777389217289652768156743",
                "168617002864170837225617953344328423347",
                "114146178033761488991947584982788165150",
                "216828252532662824052873218911733264271",
                "314156871049687367291945874927533134788"
            ]
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/commons/utils/DeSqlparserUtils.java"
        }
    },
    {
        "id": "CVE-2026-45535-b5d0913e",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "82663915937881061298585140347139922361",
                "134236751862690298098639849332803802645",
                "143691876254992914834787425243975252064",
                "167252485963271988385677111971663622433",
                "87915592003077657575432669170886376601",
                "97888718461730199425764664639973809567",
                "82872673138699303080229104293362471228",
                "63855423353122392283517627885205439462",
                "167252485963271988385677111971663622433",
                "132877933222434303111931237223548390125",
                "114146178033761488991947584982788165150",
                "216828252532662824052873218911733264271",
                "314156871049687367291945874927533134788"
            ]
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/commons/utils/SqlparserUtils.java"
        }
    },
    {
        "id": "CVE-2026-45535-b8a0cd32",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 3185.0,
            "function_hash": "284341579942495744649626256312864765717"
        },
        "source": "https://github.com/dataease/dataease/commit/22930a493d900fe3d8084b3dd4c0125abdb2a847",
        "target": {
            "function": "previewSql",
            "file": "core/core-backend/src/main/java/io/dataease/dataset/manage/DatasetDataManage.java"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45535.json"