<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:bytedance:coze_studio:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3abytedancecoze_studio/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:57:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3abytedancecoze_studio/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insufficient Validation in Coze Studio Workflow SQL Nodes</title><link>https://feed.craftedsignal.io/briefs/2026-09-coze-studio-sql-injection/</link><pubDate>Wed, 16 Sep 2026 21:57:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-coze-studio-sql-injection/</guid><description>Coze Studio versions up to 0.5.1 contain an input validation vulnerability in workflow SQL customization nodes allowing authenticated attackers to bypass workspace isolation and execute unauthorized SQL queries.</description><content:encoded><![CDATA[<p>Coze Studio versions through 0.5.1 are affected by a workspace isolation vulnerability within their workflow SQL customization nodes. The application fails to validate whether the table names provided in these nodes belong to the caller's authorized workspace. Because table identifiers are predictable, an authenticated attacker can manipulate these inputs to target memory databases belonging to other workspaces. This flaw allows for unauthorized read, insert, and delete operations across workspace boundaries. Defenders should note that this requires a user to have access to the Coze Studio environment, making it a critical risk for multi-tenant deployments where users may attempt to escalate privileges or perform cross-workspace data exfiltration.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated users to access, modify, or delete sensitive data within memory databases of other workspaces within the same Coze Studio instance. This represents a complete breach of multi-tenancy isolation. The number of impacted organizations is unknown, but any deployment utilizing version 0.5.1 or earlier is at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Coze Studio to the version following 0.5.1 as soon as it is released to remediate the input validation logic in SQL customization nodes.</li>
<li>Audit workspace logs for anomalous SQL activity originating from workflow customization nodes where the requested table identifiers do not match the expected workspace scope.</li>
<li>Implement strict workspace-level access controls to limit the number of users with permissions to create or edit workflow SQL customization nodes.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>sql-injection</category><category>multi-tenancy</category><category>cve-2026-92788</category></item></channel></rss>