VYPR

Djehuty

by 4turesearchdata

CVEs (2)

  • CVE-2026-73975HigOct 1, 2026
    risk 0.48cvss —epss —

    djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary…

  • CVE-2026-73976HigOct 1, 2026
    risk 0.39cvss —epss —

    djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does…