Report: CVE-2026-33082 - DataEase: SQL Injection in v2 Dataset Export

Report: CVE-2026-33082 - DataEase: SQL Injection in v2 Dataset Export

CVE ID :CVE-2026-33082 Published : April 16, 2026, 6:16 p.m. | 46 minutes ago Description :DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized into a filtering object and passed to WhereTree2Str.transFilterTrees for SQL translation, where user-controlled values in

CVE Details

Published
April 16, 2026
Impact: SQL injection