Executive brief
dbx is a cross-platform database client that provides a web interface for querying multiple databases. When the password authentication is not configured (a common state in fresh deployments), the web backend bypasses all access controls and exposes database query and connection APIs to the network without requiring authentication. An attacker can exploit this to execute arbitrary SQL commands, steal sensitive data, or destroy databases.
Technical details
The auth_middleware in crates/dbx-web/src/auth.rs fails to enforce authentication when password_hash is None, which occurs when the DBX_PASSWORD environment variable is unset and no stored password exists. The web backend binds by default to 0.0.0.0:4224, making the unauthenticated API routes /api/connection/connect and /api/query/execute reachable from the network. An attacker without credentials can send requests to these endpoints to leverage pre-configured database credentials and execute arbitrary SQL, resulting in data disclosure, modification, or destruction. The fix in version 0.5.51 requires proper authentication enforcement even when password_hash is None. The desktop Tauri application is unaffected because it binds only to loopback.
Affected products
- t8y2 dbx prior to 0.5.51
Timeline
- 2026-08-20: disclosed: CVE-2026-55642 published
- 2026-07-08: patched: Fix committed in version 0.5.51