Learningcircuit

Local Deep Research

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 28.05.2026 17:59:19
  • Zuletzt bearbeitet 01.06.2026 18:38:18

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title...

  • EPSS 0.25%
  • Veröffentlicht 28.05.2026 17:58:22
  • Zuletzt bearbeitet 01.06.2026 18:43:56

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 23.12.2025 00:01:19
  • Zuletzt bearbeitet 29.12.2025 16:08:52

Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's ...