Executive brief
Anyquery, a tool for querying data using SQL, contains a vulnerability in its server mode that allows unauthorized access to local files. By connecting to the server's database port, an attacker can read sensitive system files, such as passwords or private keys, that the application has permission to access. This could lead to a complete compromise of the host system's data confidentiality.
Technical details
Anyquery utilizes the hashicorp/go-getter library within its data ingestion modules. When launched in Server Mode, it binds to a TCP port and accepts MySQL protocol connections without restricting virtual table modules (like csv_reader or log_reader) to safe directories. An unauthenticated remote attacker can execute native SQLite virtual table creation queries to point these modules at sensitive local files (e.g., /etc/passwd). Because the file read operation is initiated by the Anyquery server process, the attacker can read any file the process has permissions to access. The vulnerability is addressed in version 0.4.5.
Affected products
- julien040 anyquery < 0.4.5
Timeline
- 2026-06-09: disclosed: Initial disclosure by reporter Metincloup
- 2026-07-14: advisory: GitHub Advisory published