Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable expression is executed when Baserow recalculates formula field values. Because the generated SQL runs through Baserow's database connection, the injected SQL executes with the privileges of the Baserow PostgreSQL role rather than the permissions of the authenticated application user. This issue affects Baserow: 2.3.3.
History

Wed, 02 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable expression is executed when Baserow recalculates formula field values. Because the generated SQL runs through Baserow's database connection, the injected SQL executes with the privileges of the Baserow PostgreSQL role rather than the permissions of the authenticated application user. This issue affects Baserow: 2.3.3. Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable expression is executed when Baserow recalculates formula field values. Because the generated SQL runs through Baserow's database connection, the injected SQL executes with the privileges of the Baserow PostgreSQL role rather than the permissions of the authenticated application user. This issue affects Baserow: 2.3.3.

Wed, 02 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable expression is executed when Baserow recalculates formula field values. Because the generated SQL runs through Baserow's database connection, the injected SQL executes with the privileges of the Baserow PostgreSQL role rather than the permissions of the authenticated application user. This issue affects Baserow: 2.3.3.
Title Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction
First Time appeared Baserow
Baserow baserow
Weaknesses CWE-89
CPEs cpe:2.3:a:baserow:baserow:2.3.3:*:linux:*:*:*:*:*
cpe:2.3:a:baserow:baserow:2.3.3:*:macos:*:*:*:*:*
cpe:2.3:a:baserow:baserow:2.3.3:*:windows:*:*:*:*:*
Vendors & Products Baserow
Baserow baserow
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2026-09-02T03:29:38.759Z

Updated: 2026-09-02T12:58:27.116Z

Reserved: 2026-08-13T15:37:56.088Z

Link: CVE-2026-19754

cve-icon Vulnrichment

Updated: 2026-09-02T12:58:21.412Z

cve-icon NVD

Status : Received

Published: 2026-09-02T04:17:51.537

Modified: 2026-09-02T13:17:07.763

Link: CVE-2026-19754

cve-icon Redhat

No data.