CVE-2026-75480
- EPSS 0.24%
- Veröffentlicht 17.08.2026 20:36:06
- Zuletzt bearbeitet 18.08.2026 16:18:20
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, reso...
- EPSS 0.14%
- Veröffentlicht 28.06.2026 21:30:09
- Zuletzt bearbeitet 29.06.2026 18:41:05
A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of ...
CVE-2026-40525
- EPSS 0.57%
- Veröffentlicht 17.04.2026 18:19:12
- Zuletzt bearbeitet 14.07.2026 21:16:49
OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with netw...
CVE-2026-22680
- EPSS 0.38%
- Veröffentlicht 07.04.2026 17:08:30
- Zuletzt bearbeitet 14.07.2026 16:16:51
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/...
CVE-2026-34999
- EPSS 0.42%
- Veröffentlicht 01.04.2026 13:30:30
- Zuletzt bearbeitet 14.07.2026 19:17:03
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and...
CVE-2026-28518
- EPSS 0.18%
- Veröffentlicht 03.03.2026 14:36:13
- Zuletzt bearbeitet 14.07.2026 19:16:53
OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives...
CVE-2026-22207
- EPSS 0.43%
- Veröffentlicht 26.02.2026 20:34:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to pr...