
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-7333 is a SQL injection vulnerability in the bluelabsio/records-mover Python library, affecting all versions up to and including 1.5.4. The flaw resides in the Table Object Handler component, where user-controlled input (such as schema and table names) was interpolated directly into raw SQL strings without proper sanitization. It was disclosed publicly on January 7–8, 2026, and a patch was merged into the codebase in November 2023 and released as version 1.6.0 in December 2023. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 4.8 (Medium) (Github Advisory).
The root cause is improper neutralization of special elements in SQL commands (CWE-89 / CWE-74). In affected versions, multiple components — including vertica_db_driver.py, prep.py, sources/table.py, and targets/spectrum.py — constructed SQL statements using Python f-strings with unvalidated schema and table name inputs (e.g., f"SELECT * FROM {quoted_table}", f"TRUNCATE TABLE {schema_and_table}", f"DROP TABLE {schema_and_table}"), passing them directly to sqlalchemy.text() for execution. The fix replaced these raw string constructions with SQLAlchemy's parameterized Table object, DropTable, and table.delete() constructs, which handle quoting and escaping safely. Exploitation requires local access and low privileges — an attacker must be able to influence the schema or table name values passed to the library's data movement functions (Github Advisory, Patch Commit).
A locally authenticated, low-privileged attacker who can control schema or table name inputs to the records-mover library could inject arbitrary SQL commands into the underlying database. Successful exploitation could result in unauthorized read access to sensitive data (confidentiality impact), unauthorized modification or deletion of database contents (integrity impact), and potential disruption of database availability. The scope is limited to the vulnerable system's database; no subsequent system impact is expected based on the CVSS assessment (Github Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.021% (0th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
records-mover version ≤ 1.5.4 (e.g., via pip show records-mover or inspecting pyproject.toml/setup.cfg).move(), prep_table_for_load(), or the Vertica has_table() method — for example, via a CLI argument like mvrec file2table foo.csv db1 <schema> <table>.myschema; DROP TABLE sensitive_data; --) that, when interpolated into the raw f-string SQL template, alters the intended query structure.sqlalchemy.text() and executed against the connected database, potentially reading, modifying, or deleting data depending on the database user's privileges (Patch Commit, Github Advisory).;, --, ', DROP, TRUNCATE, SELECT) within schema or table name fields; database error logs showing ProgrammingError or syntax errors from unusual query structures.Upgrade records-mover to version 1.6.0 or later, which replaces all vulnerable raw SQL string constructions with SQLAlchemy's parameterized Table, DropTable, and table.delete() constructs. The fix is available via pip install --upgrade records-mover or by applying patch commit 3f8383aa89f45d861ca081e3e9fd2cc9d0b5dfaa. As an interim measure, restrict local access to systems running affected versions and ensure that schema and table name inputs to records-mover are sourced only from trusted, controlled configurations rather than user-supplied input (Github Advisory, v1.6.0 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."