{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/coze-studio--0.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bytedance:coze_studio:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92788"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Coze Studio (\u003c= 0.5.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sql-injection","multi-tenancy","cve-2026-92788"],"_cs_type":"advisory","_cs_vendors":["ByteDance"],"content_html":"\u003cp\u003eCoze Studio versions through 0.5.1 are affected by a workspace isolation vulnerability within their workflow SQL customization nodes. The application fails to validate whether the table names provided in these nodes belong to the caller's authorized workspace. Because table identifiers are predictable, an authenticated attacker can manipulate these inputs to target memory databases belonging to other workspaces. This flaw allows for unauthorized read, insert, and delete operations across workspace boundaries. Defenders should note that this requires a user to have access to the Coze Studio environment, making it a critical risk for multi-tenant deployments where users may attempt to escalate privileges or perform cross-workspace data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to access, modify, or delete sensitive data within memory databases of other workspaces within the same Coze Studio instance. This represents a complete breach of multi-tenancy isolation. The number of impacted organizations is unknown, but any deployment utilizing version 0.5.1 or earlier is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Coze Studio to the version following 0.5.1 as soon as it is released to remediate the input validation logic in SQL customization nodes.\u003c/li\u003e\n\u003cli\u003eAudit workspace logs for anomalous SQL activity originating from workflow customization nodes where the requested table identifiers do not match the expected workspace scope.\u003c/li\u003e\n\u003cli\u003eImplement strict workspace-level access controls to limit the number of users with permissions to create or edit workflow SQL customization nodes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:57:02Z","date_published":"2026-09-16T21:57:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-coze-studio-sql-injection/","summary":"Coze Studio versions up to 0.5.1 contain an input validation vulnerability in workflow SQL customization nodes allowing authenticated attackers to bypass workspace isolation and execute unauthorized SQL queries.","title":"Insufficient Validation in Coze Studio Workflow SQL Nodes","url":"https://feed.craftedsignal.io/briefs/2026-09-coze-studio-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Coze Studio (\u003c= 0.5.1)","version":"https://jsonfeed.org/version/1.1"}