SQLite through 3.40.0, when relying on --safe for...
Critical severity
Unreviewed
Published
Dec 12, 2022
to the GitHub Advisory Database
•
Updated May 5, 2025
Description
Published by the National Vulnerability Database
Dec 12, 2022
Published to the GitHub Advisory Database
Dec 12, 2022
Last updated
May 5, 2025
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
References