VYPR

Vane

by ItzCrazyKns

CVEs (2)

  • CVE-2026-9372May 24, 2026
    risk 0.00cvss epss

    A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of…

  • CVE-2026-9371May 24, 2026
    risk 0.00cvss epss

    A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to missing authentication. The attack may be initiated remotely. The attack's…