github.com/julien040/anyquery
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/julien040/anyquerypage 1 of 1
- CVE-2026-47253HIGHCVSS 7.3EG 7.3✓ Fixed in 0.4.52026-06-10
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll with…
- CVE-2026-50006CRITICALCVSS 9.1EG 9.12026-07-14
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker …
- CVE-2026-54628HIGHCVSS 8.6EG 8.62026-07-14
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without re…
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, aut…
Check whether github.com/julien040/anyquery is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/julien040/anyquery CVEs against the assets you own.
Start Free Scan →