Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34999

Опубликовано: 01 апр. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:volcengine:openviking:*:*:*:*:*:*:*:*
Версия от 0.2.5 (включая) до 0.2.14 (исключая)

EPSS

Процентиль: 35%
0.00418
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
github
5 месяцев назад

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers can bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without providing valid credentials.

EPSS

Процентиль: 35%
0.00418
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-306