Browse all 4 CVE security advisories affecting LearningCircuit. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-43979 | Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`) — local-deep-research CWE-79 | 5.0 | Medium | 2026-05-28 |
| CVE-2026-46526 | Local Deep Research: SSRF bypass in `safe_get` — local-deep-research CWE-918 | 5.0 | Medium | 2026-05-28 |
| CVE-2025-67743 | Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service — local-deep-research CWE-918 | 6.3 | Medium | 2025-12-23 |
| CVE-2025-57806 | Local Deep Research's API keys are stored in plain text — local-deep-research CWE-312 | 5.5AI | Medium AI | 2025-09-03 |
This page lists every published CVE security advisory associated with LearningCircuit. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.