VYPR

Aix Db

by Apconw

Source repositories

CVEs (2)

  • CVE-2026-8335HigJun 10, 2026
    risk 0.46cvss epss 0.00

    A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint lacks the token validation enforced on all other application endpoints. All…

  • CVE-2026-4530MedMar 22, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument Description results in sql injection. The attack requires a local approach. The…