{
  "id": 236371,
  "title": "datasette 1.0a38",
  "url": "https://urgent.news/2026/08/06/datasette-1-0a38",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-06T18:24:34.000Z",
  "source": {
    "name": "Simon Willison",
    "slug": "simon-willison",
    "url": "https://simonwillison.net/2026/Aug/6/datasette/"
  },
  "original_language": "en",
  "account": "Datasette 1.0a38 is a software release that addresses a security vulnerability related to SQL injection. This bug could have enabled unauthorized users to execute SQL queries and gain read-only access to private tables in a database, even if they only had access to a public table. The issue arises when a Datasette instance serves both public and private tables in the same database, and access to those tables is controlled through the Datasette permissions system. To mitigate this risk, site administrators are advised to disable the \"execute-sql\" permission on the database hosting private tables. This fix is also included in Datasette version 0.65.3. The vulnerability mainly affects configurations where private and public tables are exposed within the same database instance, which is considered rare. The update was brought to light by Simon Willison on August 6, 2026. Supporters can contribute $10 per month for a regular digest of the most important developments in large language models.",
  "summary": "Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permissions system . Site administrators who serve private tables in this way are advised to disable the execute-sql permission ` on that database to prevent users from…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}