Skip to main content

Vendor/product archive

volcengine / openviking CVEs

Beta · best-effort

4 CVEs tagged to volcengine / openviking1 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-40525

Published Apr 17, 2026

OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the ap…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-22680

Published Apr 7, 2026

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve backgrou…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-34999

Published Apr 1, 2026

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected b…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-28518

Published Mar 3, 2026

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside th…

CVSS 8.4 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1