Tag
high
advisory
Anyquery Server-Side Request Forgery via Unrestricted SQLite Virtual Table Modules
3 rules 4 TTPsUnauthenticated attackers can exploit a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-54628) in Anyquery's `server` mode (versions prior to 0.4.5) by creating SQLite virtual tables that fetch internal network resources or cloud metadata, leading to internal network mapping and exfiltration of sensitive information like cloud credentials.
Anyquery
ssrf
vulnerability
local-file-read
linux
data-exfiltration
3r
4t
critical
advisory
Arbitrary XML Schema Definition Processing in guardrails-detectors Leads to SSRF and Local File Read
3 TTPs 1 CVEA flaw in the 'file_type' content detector of 'guardrails-detectors' allows a remote attacker to provide an arbitrary XML Schema Definition (XSD) string, leading to server-side request forgery (SSRF) and local file reads, potentially exposing sensitive information such as cloud provider credentials or granting access to internal network services.
guardrails-detectors
vulnerability
ssrf
local-file-read
info-disclosure
guardrails
3t
1c