An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
References
| Link | Resource |
|---|---|
| https://github.com/h2database/h2database | Not Applicable |
| https://github.com/xyyzxc/CVE-2025-56819 | Third Party Advisory |
| https://h2database.com/html/features.html#runscript | Not Applicable |
Configurations
History
No history.
Information
Published : 2025-09-24 16:15
Updated : 2025-10-10 21:30
NVD link : CVE-2025-56819
Mitre link : CVE-2025-56819
CVE.ORG link : CVE-2025-56819
JSON object : View
Products Affected
running-elephant
- datart
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
