Back to overview

CVE-2026-13483

LOW
3.1
CVSS 3.1
Description
A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component Credential Storage. This manipulation causes insufficient verification of data authenticity. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is described as difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.

Metadata

CVE ID
CVE-2026-13483
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-27 15:02 UTC
Published
2026-06-28 05:45 UTC
Last updated
2026-06-28 05:45 UTC
Primary CWE
CWE-345
Insufficient Verification of Data Authenticity
Vendor / Product
arc53 / DocsGPT
Sources
cve.org  ·  NVD

Severity & Metrics

3.1 LOW CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
arc53 DocsGPT 0.1, 0.2, 0.3, 0.4 …
Weakness (CWE)
CWESourceDescription
CWE-345 cna Insufficient Verification of Data Authenticity
CVSS scores (4)
ScoreSeverityVersionSourceVector
3.1 LOW 3.1 cna CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
3.1 LOW 3.0 cna CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
2.3 LOW 4.0 cna CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
2.1 N/D 2.0 cna AV:N/AC:H/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR
References (7)
Back to overview