CVE-2026-91201
- EPSS 0.14%
- Veröffentlicht 14.09.2026 22:10:58
- Zuletzt bearbeitet 23.09.2026 17:17:44
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener durin...
CVE-2026-13483
- EPSS 0.1%
- Veröffentlicht 28.06.2026 05:45:08
- Zuletzt bearbeitet 29.06.2026 18:43:23
A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component Credential Storage. This manipulation causes insufficient verification of da...
CVE-2026-26015
- EPSS 1.17%
- Veröffentlicht 29.04.2026 17:37:25
- Zuletzt bearbeitet 06.05.2026 20:16:31
DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior...