Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpqq-qx8w-x7gh

Опубликовано: 17 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.

EPSS

Процентиль: 15%
0.00238
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret material belonging to other users in the same account without administrative privileges.

EPSS

Процентиль: 15%
0.00238
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-863