VYPR

opencost

by Opencost

CVEs (2)

  • CVE-2026-44300higJul 14, 2026
    risk 0.45cvss epss

    ## Summary OpenCost contains an unauthenticated file write vulnerability in the `/serviceKey` endpoint that allows remote attackers to overwrite the GCP service account key file without authentication. This can lead to service disruption, credential theft, and potential…

  • CVE-2026-67349Jul 30, 2026
    risk 0.00cvss epss 0.00

    OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers…