CVE-2024-55081

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.

Published 2024-12-19. Last modified 2026-06-17.