CRITICAL
9 CVE-2026-47252 Published 17 Sept 2026
Anyquery Chrome Plugin Command Injection
Worried this affects your website?
Anyquery, an SQL query engine for macOS, is vulnerable to command injection via its Chrome plugin (and equivalents in Brave, Edge, and Safari).
Prior to version 0.4.5, authenticated users with INSERT or UPDATE access to specific tables can exploit this issue by crafting a URL with quote and newline characters to execute arbitrary operating-system commands.
Reference: CVE-2026-47252 on NVD
← Back to Security News