Unknown · Epsilla-Cloud Vectordb · CVE-2026-18852
**Name of the Vulnerable Software and Affected Versions**
epsilla-cloud vectordb versions prior to 0.3.18
**Description**
An issue exists in the Filter Parser component within the file engine/query/expr/expr.cpp. Specifically, the `SplitTokens()` and `ShuntingYard()` functions fail to properly check for unusual conditions, which can be manipulated by a local attacker.
**Recommendations**
As a temporary workaround, restrict local access to the Filter Parser component to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.