MEDIUM
erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection
Published Mar 23, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.32%
Description
A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the component MCP Tool Interface. This manipulation causes sql injection hibernate. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 1.13.0
- 1.13.1
- 1.13.2
- 1.13.3
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14473 Advisory
- https://fx4tqqfvdw4.feishu.cn/docx/EunDdwORZoG3uzxpLykcj24mncJ?from=from_copylink exploit
- https://vuldb.com/?ctiid.352430 signaturepermissions-required
- https://vuldb.com/?id.352430 vdb-entrytechnical-description
- https://vuldb.com/?submit.775593 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14473 | Advisory | |
| https://fx4tqqfvdw4.feishu.cn/docx/EunDdwORZoG3uzxpLykcj24mncJ?from=from_copylink | exploit | |
| https://vuldb.com/?ctiid.352430 | signaturepermissions-required | |
| https://vuldb.com/?id.352430 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.775593 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 23, 2026
Updated Mar 25, 2026
Reserved Mar 22, 2026
Link CVE-2026-4593
CISA Vulnrichment
Updated Mar 25, 2026
Red Hat
No data
GitHub
No data