sqladmin
SQLAlchemy Admin for FastAPI and Starlette
Activity
- Latest release
- 2w ago
- Total releases
- 58
- Cadence
- ~20 days
- Last 12 months
- 14
Reach
- Stars
- 2.8k
Details
- License
- BSD-3-Clause
- First release
- Dec 21, 2021
| Version | Released | |
|---|---|---|
0.31.1
patch
| ||
0.31.0
minor
| ||
0.30.0
minor
| ||
0.29.0
minor
| ||
0.28.0
minor
| ||
0.27.2
patch
| ||
0.27.1
patch
| ||
0.27.0
minor
1 CVE
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.26.0
minor
1 CVE
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.25.1
patch
1 CVE
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.25.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.24.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.23.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.22.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.21.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.20.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.20.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.19.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.17.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.16.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.16.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.15.2
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.15.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.15.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.14.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.13.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.11.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.10.3
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.10.2
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.10.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.10.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.9.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.8.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.7.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2.1
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.12
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.11
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.10
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.9
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.8
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.7
patch
2 CVEs
CVE-2026-54529
PYSEC-2026-3922
GHSA-ccg5-9c8w-xh6v
Sep 10, 2026
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Summary
Root cause
ExploitationA single request leaks the relative ordering of an unexposed column; the Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 39 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.25.1
0.26.0
0.27.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.27.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-46645
PYSEC-2026-3073
GHSA-54mc-gghv-4cfj
Jul 13, 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe If a developer restricts model access by overriding Affected endpoint:
All other endpoints enforce both checks: | Endpoint | Note: before this fix, PatchesTwo changes were made to
WorkaroundsNone. Developers relying on Affected versions
0.0.0
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
+ 36 more Show less
0.1.8
0.1.9
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.15.0
0.15.1
0.15.2
0.16.0
0.16.1
0.17.0
0.18.0
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.3.0
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.9.0
Fixed in
0.25.1
References
Updated Jul 13, 2026 · Source: OSV.dev |