Press "Enter" to skip to content

SQL Copilot “Read-Only” Mode Wasn’t

Rebecca Lewis reads a CVE:

I was in Italy for a month. While I was gone, somebody got sysadmin out of SQL Copilot with a variable.

The vulnerability is CVE-2026-65669, the SSMS 22 Copilot bug I wrote about early September. The full write-up went public on September 30th, and the detail that stuck with me is how Copilot’s ‘read-only mode’ was enforced. It wasn’t a permission. It was a regex blocklist.

That blocklist is the same control we have watched fail against SQL injection for twenty years. Before I get to Copilot, let’s build one here and see it fail.

These sorts of blacklists almost never work against a committed attacker because, unless you fully enumerate the possible domain, there’s an opportunity for someone to slip through, and that’s exactly what happened here.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.