Volcengine

Openviking

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 17.08.2026 20:36:06
  • Zuletzt bearbeitet 18.08.2026 16:18:20

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, reso...

  • EPSS 0.14%
  • Veröffentlicht 28.06.2026 21:30:09
  • Zuletzt bearbeitet 29.06.2026 18:41:05

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of ...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 17.04.2026 18:19:12
  • Zuletzt bearbeitet 14.07.2026 21:16:49

OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with netw...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 07.04.2026 17:08:30
  • Zuletzt bearbeitet 14.07.2026 16:16:51

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/...

  • EPSS 0.42%
  • Veröffentlicht 01.04.2026 13:30:30
  • Zuletzt bearbeitet 14.07.2026 19:17:03

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and...

  • EPSS 0.18%
  • Veröffentlicht 03.03.2026 14:36:13
  • Zuletzt bearbeitet 14.07.2026 19:16:53

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives...

  • EPSS 0.43%
  • Veröffentlicht 26.02.2026 20:34:30
  • Zuletzt bearbeitet 15.04.2026 00:35:42

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to pr...