Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-51876

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DeepTutor 1.4.0 在书籍确认流程中存在授权绕过漏洞。未认证或未授权的攻击者可以利用公开暴露的 book_id,对现有书籍提交 confirm-proposal 请求,从而导致持久化元数据和脊柱内容(spine content)被未经授权的覆盖。

AI Predicted 8.6 Difficulty: Easy EPSS 0.15% · P4

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
n/a n/a n/a affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-51876

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-51876

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-51876

请登录查看更多情报信息。

Proof of Concept for CVE-2026-51876 (1)

Same Patch Batch · n/a · 2026-10-01 · 21 CVEs total

CVE-2026-103484 8.8 HIGH pgvector buffer overflow in IVFFlat index build
CVE-2026-103531 5.5 MEDIUM OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow
CVE-2026-51875 Devika v1.0存在路径遍历漏洞
CVE-2026-51892 RagFlow 0.24.0 /v1/document/get/ 接口访问控制错误漏洞
CVE-2026-51896 RagFlow 0.25.3恢复模块越权访问漏洞
CVE-2026-51882 Langchain-Chatchat 0.3.0 文件上传路径穿越漏洞
CVE-2026-51886 LangFlow v1.9.3代码注入漏洞
CVE-2026-51878 DeepTutor 1.4.0 对象标识符授权绕过漏洞
CVE-2026-51873 Devika v1.0目录遍历漏洞
CVE-2026-51881 DeepTutor 1.4.0远程代码注入漏洞
CVE-2026-51879 DeepTutor 1.4.0 认证绕过漏洞
CVE-2026-51897 RAGFlow 0.24.0 get_dataset接口存在命令执行漏洞
CVE-2026-51884 Langchain Chatchat 0.3.1临时文档上传路径遍历漏洞
CVE-2026-51888 Langflow v1.8.4 目录遍历漏洞
CVE-2026-51893 RagFlow 0.24.0 越权访问漏洞
CVE-2026-51880 Deeptutor 1.4.0 EditFileTool路径遍历漏洞
CVE-2026-51895 Ragflow 0.24.0及之前版本存在更新元数据不当访问控制漏洞
CVE-2026-51874 Devika v1.0路径穿越漏洞
CVE-2026-51894 RAGFlow 0.24.0 任意文件读取漏洞
CVE-2026-51883 Langchain-Chatchat 0.3.x 知识库创建接口路径穿越漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-51876

No comments yet


Leave a comment