All 4 CVE vulnerabilities found in local-deep-research, with AI-generated Chinese analysis, references, and POCs.
Vendor: LearningCircuit
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-43979 | Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`) CWE-79 | 5.0 | Medium | 2026-05-28 |
| CVE-2026-46526 | Local Deep Research: SSRF bypass in `safe_get` CWE-918 | 5.0 | Medium | 2026-05-28 |
| CVE-2025-67743 | Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service CWE-918 | 6.3 | Medium | 2025-12-23 |
| CVE-2025-57806 | Local Deep Research's API keys are stored in plain text CWE-312 | 5.5AI | Medium AI | 2025-09-03 |
All 4 known CVE vulnerabilities affecting local-deep-research with full Chinese analysis, references, and POCs where available.