
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21892 is a SQL Injection vulnerability in the parsl-visualize component of Parsl (Python Parallel Scripting Library), a parallel scripting framework developed at the University of Chicago. The flaw affects all Parsl versions prior to 2026.01.05 (specifically confirmed in version 2025.12.1) and was published on January 6, 2026, with NVD publication on January 8, 2026. An unauthenticated attacker with network access to the visualization dashboard can inject arbitrary SQL commands via the workflow_id URL parameter. The CNA (GitHub) assigned a CVSS v3.1 score of 5.3 (Medium), while NVD's independent assessment rates it 7.3 (High) (Github Advisory, Parsl Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), located in parsl/monitoring/visualization/views.py. Multiple Flask route handlers pass the workflow_id URL parameter directly into raw SQL query strings using Python's % string formatting operator without any sanitization or parameterization. Two specific vulnerable patterns were identified: WHERE task.run_id='%s'" % (workflow_id) in the DAG view handler, and a similar pattern in the resource usage view using pd.read_sql_query("...run_id='%s'..." % (workflow_id, workflow_id), db.engine). The attack requires no authentication and no user interaction — only network access to the running parsl-visualize server (Github Advisory, Patch Commit).
Successful exploitation can lead to data exfiltration via UNION-based injection, allowing an attacker to dump the entire contents of the Parsl monitoring database, which may include sensitive environment variables, task parameters, and host information. An attacker can also bypass workflow-level access controls using boolean injection (e.g., ' OR '1'='1) to view data from workflows they are not authorized to access. Additionally, time-based or resource-intensive SQL payloads (e.g., using randomblob) can cause denial of service against the visualization server or the underlying SQLite database (Github Advisory).
A proof-of-concept (PoC) demonstrating boolean-based blind SQL injection is publicly documented in the GitHub Security Advisory, making exploitation straightforward for any attacker with access to the dashboard. The advisory was tagged as an "Exploit" reference by both CISA-ADP and NVD. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.038% (Feedly data) to 0.106% (GitHub Advisory), placing it in the 28th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Parsl Advisory).
parsl-visualize servers (default port 8080) using network scanning tools or by checking for exposed Parsl monitoring dashboards. Confirm the instance is running a vulnerable version prior to 2026.01.05.workflow_id (e.g., a UUID or default-run), or attempt common identifiers. A valid ID is needed as the base for injection.http://<host>:8080/workflow/' AND '1'='0/dag_group_by_statesAn empty graph confirms the false condition was evaluated. Then confirm with a true condition:http://<host>:8080/workflow/' AND '1'='1/dag_group_by_statesA populated graph confirms SQL injection is active.randomblob in SQLite) to degrade or crash the visualization server or database (Github Advisory, Parsl Advisory)./workflow/<id>/dag_group_by_states or /workflow/<id>/ endpoints where <id> contains SQL metacharacters such as ', %20AND%20, UNION, SELECT, OR, or randomblob.workflow_id path segment (e.g., %27, %20AND%20, UNION+SELECT); repeated requests to visualization endpoints with varying injected conditions.Upgrade Parsl to version 2026.01.05 or later, which fixes the vulnerability by replacing unsafe Python % string formatting with SQLAlchemy parameterized queries using named bind parameters (:run_id) and sqlalchemy.text() (Patch Commit). If immediate upgrade is not possible, restrict network access to the parsl-visualize server so it is only accessible to trusted users (e.g., via firewall rules or binding to localhost). Do not expose the parsl-visualize dashboard to untrusted networks, as it is designed for internal monitoring use (Github Advisory).
The vulnerability was reported by security researcher viralvaghela and acknowledged by Parsl maintainer benclifford, who noted in the patch commit that in the default configuration the practical security impact may be limited because the parsl-visualize database is already intended to be public and SQLite restricts multi-statement execution (Patch Commit). The advisory was picked up by Debian security advisories and Linux security news outlets, and detection plugins were added by Nessus (Tenable) and Qualys shortly after disclosure (Github Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."