Hackers are chaining together two newly discovered flaws to achieve remote code execution.
Any text-to-SQL benchmark should address the difficulties of real-world data stores.