PT-2026-47243 · Grepai · Grepai

·

CVE-2026-11481

·

Published

2026-06-08

·

Updated

2026-09-04

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions yoanbernabeu grepai versions prior to 0.35.0
Description The Postgres Embedding Cache component contains an issue where the PostgresStore.LookupByContentHash() function in the indexer/chunker.go file uses a weak hash. A local attacker can manipulate the content hash argument to exploit this. The attack is characterized by high complexity and is difficult to execute.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11481
GHSA-Q76H-P6JH-9RW3
GO-2026-6128
OPENSUSE-SU-2026:21761-1

Affected Products

Grepai