Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against other workspaces' memory databases to read, insert, or delete data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against other workspaces' memory databases to read, insert, or delete data. | |
| Title | Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node | |
| First Time appeared |
Coze
Coze coze Studio |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:coze:coze_studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coze
Coze coze Studio |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:44.626Z
Reserved: 2026-09-16T19:31:52.771Z
Link: CVE-2026-92788
No data.
Status : Received
Published: 2026-09-16T21:17:28.180
Modified: 2026-09-16T21:17:28.180
Link: CVE-2026-92788
No data.
OpenCVE Enrichment
No data.
Weaknesses