Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x546-prg5-fvp8

Опубликовано: 10 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.

A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.

EPSS

Процентиль: 9%
0.00195
Низкий

7.1 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
около 2 месяцев назад

A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All releases up to 1.2.4 are considered vulnerable. Status of next releases is unknown as the vulnerability has not been addressed by any patch.

EPSS

Процентиль: 9%
0.00195
Низкий

7.1 High

CVSS4

Дефекты

CWE-306