CVE-2026-2532
A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3.
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoints/embedding_config.py of the component IP Address Handler. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.0.4 and 3.1.0 is capable of addressing this issue. The patch is named da853fdd8cbe9d42053b45d83f25708ba29b8b27. It is suggested to upgrade the affected component.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- lintsinghua/deepaudit
- Source
- cna@vuldb.com
References
- https://github.com/lintsinghua/DeepAudit/Product
- https://github.com/lintsinghua/DeepAudit/commit/da853fdd8cbe9d42053b45d83f25708ba29b8b27Patch
- https://github.com/lintsinghua/DeepAudit/issues/144Issue Tracking
- https://github.com/lintsinghua/DeepAudit/pull/145Issue Tracking, Patch
- https://github.com/lintsinghua/DeepAudit/releases/tag/v3.0.4Release Notes
- https://vuldb.com/?ctiid.346120Permissions Required, VDB Entry
- https://vuldb.com/?id.346120Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.748220Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.