A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool.py of the component SqlTool. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-5596 is a SQL injection vulnerability in griptape-ai's SqlTool component (version 0.19.4) that allows remote attackers to manipulate SQL queries through the griptape/tools/sql/tool.py file. The vulnerability has a CVSS score of 6.3 and is now publicly exploited with no vendor response.
ثغرة حقن SQL في مكون SqlTool من griptape-ai الإصدار 0.19.4 تسمح بمعالجة غير آمنة لاستعلامات قاعدة البيانات. يمكن استغلال الثغرة عن بعد من خلال معالجة المدخلات غير المصفاة في ملف griptape/tools/sql/tool.py.
A SQL injection flaw exists in griptape-ai griptape 0.19.4's SqlTool that enables remote SQL query manipulation. The exploit is publicly available and the vendor has not responded to early disclosure notifications.
Immediately upgrade griptape-ai to a patched version beyond 0.19.4. Implement input validation and parameterized queries for all SQL operations. Apply Web Application Firewall (WAF) rules to detect and block SQL injection attempts. Conduct security code review of SqlTool implementation and restrict database user permissions to minimum required privileges.
قم بالترقية الفورية إلى إصدار مصحح من griptape-ai بعد 0.19.4. طبق التحقق من صحة المدخلات والاستعلامات المعاملة لجميع العمليات. طبق قواعد جدار حماية تطبيقات الويب لكشف محاولات حقن SQL. أجرِ مراجعة أمان شاملة وقيد صلاحيات قاعدة البيانات.