CVE-2026-28677
- EPSS 0.04%
- Veröffentlicht 06.03.2026 04:23:23
- Zuletzt bearbeitet 06.03.2026 05:16:36
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline accepted user-controlled remote URLs with incomplete destination restrictions. Although priv...
CVE-2026-28676
- EPSS 0.05%
- Veröffentlicht 06.03.2026 04:23:12
- Zuletzt bearbeitet 06.03.2026 05:16:36
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers used path construction patterns that did not uniformly enforce base-directory containment. ...
CVE-2026-28675
- EPSS 0.03%
- Veröffentlicht 06.03.2026 04:22:58
- Zuletzt bearbeitet 06.03.2026 05:16:35
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints returned raw exception strings to clients. Additionally, login token material was exposed in UI/rende...
CVE-2026-27189
- EPSS 0.01%
- Veröffentlicht 21.02.2026 00:01:46
- Zuletzt bearbeitet 23.02.2026 20:48:59
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below, use non-atomic and insufficiently synchronized local JSON persistence flows, potentially causing concurrent operat...
CVE-2026-27170
- EPSS 0.05%
- Veröffentlicht 20.02.2026 23:58:22
- Zuletzt bearbeitet 23.02.2026 20:50:25
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest allows overly permissive server-side fetch behavior and can be coerced into requesting unsafe target...
CVE-2026-27169
- EPSS 0.05%
- Veröffentlicht 20.02.2026 23:51:45
- Zuletzt bearbeitet 23.02.2026 20:50:36
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces using unsafe HTML interpolation patterns, leading to X...