Volcengine · Openviking · CVE-2026-13507
**Name of the Vulnerable Software and Affected Versions**
volcengine OpenViking versions prior to 0.3.22
**Description**
Insufficient verification of data authenticity exists within the Local VectorDB Primary-key Label Handler component. The issue occurs in the `str to uint64()` function located in the `openviking/storage/vectordb/utils/str to uint64.py` file when processing the `ID` argument. This flaw allows for a remote attack, although the exploitation process is reported as highly complex and difficult.
**Recommendations**
As a temporary workaround, restrict the use of the `str to uint64()` function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.