VulnerabilityAnalyzed
CVE-2026-8757
A vulnerability was found in adenhq hive up to 0.11.0.
MEDIUM 5.5EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the component Delete Request Handler. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- adenhq/hive
- Source
- cna@vuldb.com
References
- https://gist.github.com/YLChen-007/ff3ff201b05d13d41f949f86e9187bd2Third Party Advisory
- https://vuldb.com/submit/811276Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/364384Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/364384/ctiPermissions Required, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.