datasette 0.65.3+ds-1 (unstable and testing) is affected by upstream advisory GHSA-h547-rmjf-5m2m, table permission bypass via a trailing newline in the table name. CVSS 7.5 (high). No CVE assigned yet. https://github.com/simonw/datasette/security/advisories/GHSA-h547-rmjf-5m2m A request for a table name with a trailing line feed, for example /db/secret~0A/1.json, bypasses the table-level permission check and returns rows from a table the actor is not allowed to read. The identifier check used re.match() with a $ anchor, which also matches before a trailing newline, so the unquoted name reached SQL and SQLite resolved it to the protected table. Reproduced against 0.65.3+ds-1 as installed from unstable. Fixed upstream in 0.65.5. The Debian fix, 0.65.5+ds-1 (urgency=high), is prepared on Salsa and awaiting sponsorship: https://salsa.debian.org/python-team/packages/datasette That upload also brings in upstream 0.65.4, which has no advisory of its own but hardens the same area: case-insensitive table permission checks, permission checks on intermediate tables used by through filters, SQL identifier escaping in row queries and pagination, and Cache-Control on private responses. datasette has never shipped in a stable release (first upload December 2025), so only unstable and testing are affected and no backport is needed.
We believe that the bug you reported is fixed in the latest version of
datasette, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148576@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Mahangu Weerasinghe <mahangu@gmail.com> (supplier of updated datasette package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 09:22:59 +0530
Source: datasette
Built-For-Profiles: noudeb
Architecture: source
Version: 0.65.5+ds-1
Distribution: unstable
Urgency: high
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Mahangu Weerasinghe <mahangu@gmail.com>
Closes: 1148576
Changes:
datasette (0.65.5+ds-1) unstable; urgency=high
.
* New upstream security releases 0.65.4 and 0.65.5.
- Fix a trailing newline in a requested table name bypassing table
permissions and exposing private rows (GHSA-h547-rmjf-5m2m).
(Closes: #1148576)
- Fix case-insensitive table permission checks and require access to
intermediate tables used by through filters.
- Fix SQL identifier escaping in row queries and pagination, and
parameterize full-text search index detection.
- Prevent shared caching of private and personalized responses.
- Disable SQLite extension loading after configured extensions load.
- Fix task IDs for non-blocking writes.
* Refresh patches for the updated upstream setup.py and changelog.
Checksums-Sha1:
bbaa486a2999599d2fc283038903db50ec39a704 2684 datasette_0.65.5+ds-1.dsc
76570282b9c1916818636f9db44509bb6b7fbde8 417720 datasette_0.65.5+ds.orig.tar.xz
cde1c29597002748795541604da0bc6ee12310e6 131232 datasette_0.65.5+ds-1.debian.tar.xz
c271baa7934befed37872281e6c23ed1c17d66a5 9784 datasette_0.65.5+ds-1_source.buildinfo
Checksums-Sha256:
f761cb3aa83d4c7a2457682f1d31125c6e111b7c6962ad5c51ddc3b0809e56a4 2684 datasette_0.65.5+ds-1.dsc
074f240201f10c637b6f73c7da694510484368702d111711c820b83a27b28872 417720 datasette_0.65.5+ds.orig.tar.xz
721cfad29e70cefe7e9cc4b8291005607957b6aa4d0056e5d9bacd350dafdd2b 131232 datasette_0.65.5+ds-1.debian.tar.xz
4c81adba8a27fee7439317497cd689b2ad92cb95c84da908210f3220e599b4ab 9784 datasette_0.65.5+ds-1_source.buildinfo
Files:
25d8f774697aad64976c10e573681352 2684 database - datasette_0.65.5+ds-1.dsc
9f376d6b6711ff97e22929629d512ff1 417720 database - datasette_0.65.5+ds.orig.tar.xz
a7a87f21b8cc05eb13ac4eb3d76d1175 131232 database - datasette_0.65.5+ds-1.debian.tar.xz
7d697ac59f362d63e79a6802c058d1c6 9784 database - datasette_0.65.5+ds-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEd8lhnEnWos3N8v+qQoMEoXSNzHoFAmqw7ykACgkQQoMEoXSN
zHoowQ//S5G/G4AvRTGibGFPAk8nUQpFSQHheETHkPq1+bYTvAUdhODtV6jsQtHH
J4Qyuld03+gU85hgAEbo7awsMIAGHdMSiKXsTIChuW2a+tDL+wZnFotX7Wwzg01a
DfEIJDkGUxIQeVO4LPHfNg+U/8wFiraT6R4f3orQSVv5jMNxwhwu4jMk+LkYDM6y
wjHIJNaVoAQop4lb1lx72wVTLh1eCOcZErwzf9xk7c8IucKuhEljR3xjzvfXdOwT
m8k0fusWpPu6/y/Brhc4XQKWamJUeXrxA6C/XdeKiY3Q3NrZWVYqLBKGeZ9uzjri
9g2tJK/5vrroAfRb4NE0mBzn+ih20uGWL0LpIDjfLbwfMvpG/Ns36Vh8BttNtTtN
CHwfotHR7EB0Nw2cNv49ZnOiZ4//4ojyoAVCAnUMqkpXsf7edBOaCAtaTcjtmLff
JP8/C/mJaJClj4+E3r7DRgxf7p8Z86YnewnFJkuz/mvMVWcBpgqbkGk9nquuxFWh
veIiQvmDgYCLxvhiwpXIo1OkQD7iuc6Tuv+msg+rrPGKv6IEVQbRpVmF4Df577rL
QvIk/nwHj+8IcYabOlUrLvaw3DnOZycwQ2s3ux+ZfViKD9cDJk/IcRNt3hfMcAYu
ncViyrCOXKmntaG1dKmdllHGgF+GH5aPSG31udLdb9kmfwI+qes=
=Slwx
-----END PGP SIGNATURE-----