CVE-2026-11466
5.4 MEDIUMA weakness has been identified in zilliztech deep-searcher up to 0.0.2
Published: 2026-06-07 · Last updated: 2026-06-08
Severity and scoring
- CVSS
- 5.4 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- CWE
- CWE-266, CWE-284
Description
A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-11466
- [Other]https://github.com/zilliztech/deep-searcher/
- [Other]https://github.com/zilliztech/deep-searcher/issues/267
- [Other]https://github.com/zilliztech/deep-searcher/pull/268
- [Other]https://vuldb.com/cve/CVE-2026-11466
- [Other]https://vuldb.com/submit/833652
- [Other]https://vuldb.com/vuln/369086
- [Other]https://vuldb.com/vuln/369086/cti
Related CVEs
Same CWE
- CVE-2026-46695 — Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to ru... (10.0 CRITICAL)
- CVE-2026-50564 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)
- CVE-2026-50563 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)
- CVE-2026-50545 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)
- CVE-2026-49824 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (8.5 HIGH)