datasette 1.0a38

· · Aug. 6, 2026, 9:05 p.m.
Summary
The blog post announces the release of Datasette 1.0a38, which addresses a critical SQL injection vulnerability affecting instances with mixed public and private tables. Administrators are advised to disable the execute-sql permission on such databases to prevent unauthorized access to private data. The fix is also included in a previous version, 0.65.3. The author notes that the configuration exposing both public and private tables in the same database is likely rare.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →