Security: julien040/anyquery
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete fix of GHSA-j4wj-p47h-f9cc - a third file-URI shape (file::http://host/abs/path forced getter) bypasses the allow-dirs sandboxGHSA-rj3v-75f4-r542 published
Aug 5, 2026 by julien040Moderate -
Unauthenticated Remote Query Execution via GPT Tunnel APIGHSA-cgx9-879j-533x published
Aug 5, 2026 by julien040High -
Server-mode sandbox arbitrary file write via ATTACH / VACUUM INTO with `?mode=memory&mode=rwc`GHSA-7jrp-4mmv-mw39 published
Aug 5, 2026 by julien040High -
Dev-mode UDFs bypass server sandbox denylist enabling unauthenticated filesystem oracle (conditional RCE)GHSA-4rr9-66j6-r74m published
Aug 5, 2026 by julien040Low -
Path Traversal: sandbox can be bypassed via file URI parsingGHSA-j4wj-p47h-f9cc published
Jul 3, 2026 by julien040Moderate -
Remote query files executed through anyquery run can invoke local shell commands via dot commandsGHSA-xhv3-pjg4-555g published
Aug 5, 2026 by julien040High -
Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory DeletionGHSA-j9rx-rppg-6hh4 published
Jun 9, 2026 by julien040High -
AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari)GHSA-hrj8-hjv8-mgwc published
Jun 7, 2026 by julien040Critical -
Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server ModeGHSA-mf78-3rpf-r784 published
Jun 9, 2026 by julien040High -
Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server ModeGHSA-hwrq-8wxh-q4xv published
Jun 9, 2026 by julien040High