PT-2026-67892 · Unknown · Epsilla-Cloud Vectordb

·

CVE-2026-18852

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions epsilla-cloud vectordb versions prior to 0.3.18
Description An issue exists in the Filter Parser component within the file engine/query/expr/expr.cpp. Specifically, the SplitTokens() and ShuntingYard() functions fail to properly check for unusual conditions, which can be manipulated by a local attacker.
Recommendations As a temporary workaround, restrict local access to the Filter Parser component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18852

Affected Products

Epsilla-Cloud Vectordb