WhisperX tag archive

#read-only bypass

This page collects WhisperX intelligence signals tagged #read-only bypass. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-29 05:54:10 · GitHub Issues

1. Apache Superset Reverts CVE-2024-55633 Fix, Reopening SQLLab PostgreSQL Read-Only Bypass

A GitHub pull request has been opened to revert the patch addressing CVE-2024-55633 in Apache Superset's SQLLab, effectively reintroducing a security vulnerability that allows crafted DML statements to bypass read-only restrictions on PostgreSQL databases. The revert removes EXPLAIN ANALYZE DML detection logic, potenti...

The Lab · 2026-04-30 18:54:14 · GitHub Issues

2. Apache Superset SQLLab Flaw Bypasses Read-Only Query Validation on Postgres Databases

A critical Improper Authorization vulnerability in Apache Superset's SQLLab feature allows authenticated users to execute write operations on Postgres analytic databases that should be restricted to read-only access. The flaw stems from improper validation of SQL DML statements, enabling specially crafted queries to by...