VYPR

Verba

by Weaviate

CVEs (2)

  • CVE-2026-65318HigJul 21, 2026
    risk 0.00cvss 8.6epss 0.01

    Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint.…

  • CVE-2026-65317HigJul 21, 2026
    risk 0.00cvss 8.6epss 0.01

    Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and…