datasette 1.0a38
Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permissions system . Site administrators who serve private tables in this way are advised to disable the execute-sql permission ` on that database to prevent users from…
Datasette 1.0a38 is a software release that addresses a security vulnerability related to SQL injection. This bug could have enabled unauthorized users to execute SQL queries and gain read-only access to private tables in a database, even if they only had access to a public table. The issue arises when a Datasette instance serves both public and private tables in the same database, and access to those tables is controlled through the Datasette permissions system.
To mitigate this risk, site administrators are advised to disable the "execute-sql" permission on the database hosting private tables. This fix is also included in Datasette version 0.65.3. The vulnerability mainly affects configurations where private and public tables are exposed within the same database instance, which is considered rare.
The update was brought to light by Simon Willison on August 6, 2026. Supporters can contribute $10 per month for a regular digest of the most important developments in large language models.
Written by urgent.news from Simon Willison's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.