VoltAgent VoltAgent是VoltAgent组织的一个用于构建、编排与运行AI智能体工作流的开发框架。 VoltAgent 2.1.17及之前版本存在安全漏洞,该漏洞源于Memory REST API组件的handleGetMemoryConversation函数对conversationId参数操作可能导致授权不当,攻击者可能从远程利用此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | VoltAgent | 2.1.0 |
cpe:2.3:a:voltagent:voltagent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13509 | 6.3 MEDIUM | RAGapp Knowledge File files.py FileHandler.remove_file path traversal |
| CVE-2026-13512 | 6.3 MEDIUM | Databend Tenant client_session_manager.rs state_key authorization |
| CVE-2026-13484 | 5.0 MEDIUM | MLflow Experiment-scoped Label Schema CRUD API authorization |
No comments yet