VYPR
Vendor

Skypilot Org

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2026-75481HigAug 17, 2026
    risk 0.50cvss 8.8epss 0.00

    SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its bearer token to gain administrative…

  • CVE-2026-13482LowJun 28, 2026
    risk 0.00cvss 3.7epss 0.00

    A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The manipulation results in use of weak hash. The attack may be performed from remote. This attack is…