datasette 1.0a38
Datasette patches SQL injection flaw exposing private tables to public users
“The bug that has been fixed would have allowed users with access to any public table to execute SQL injection attacks despite that restriction, giving them read-only access to data in private tables in the same database.”
Datasette 1.0a38 patches a SQL injection vulnerability affecting instances that mix public and private tables in the same database. The flaw allowed users with public table access to bypass permissions and read private table data via raw SQL. The impact is limited as this mixed-access configuration is reportedly rare.