Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

danswer-ai — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting danswer-ai. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Danswer-ai is an open-source search platform for internal knowledge bases and document retrieval. Historically, it has been vulnerable to multiple remote code execution (RCE) flaws, cross-site scripting (XSS), and privilege escalation issues, with 11 CVEs recorded to date. Notable security characteristics include its reliance on third-party dependencies and frequent exposure of sensitive endpoints. The platform has experienced multiple critical vulnerabilities affecting authentication and data access, though no major public security incidents have been widely reported. Its architecture presents several attack surfaces, particularly in API integrations and user authentication mechanisms.

Found 10 results / 11 Clear Filters
Top products by danswer-ai: danswer-ai/danswer danswer
CVE ID Title CVSS Severity Published
CVE-2024-7767 Improper Access Control in danswer-ai/danswer — danswer-ai/danswer CWE-862 8.3 - 2025-03-20
CVE-2024-9612 Unauthorized Access in danswer-ai/danswer — danswer-ai/danswer CWE-1100 4.9 - 2025-03-20
CVE-2024-8057 Improper Access Control in danswer-ai/danswer — danswer-ai/danswer CWE-306 9.8 - 2025-03-20
CVE-2024-9617 IDOR in danswer-ai/danswer — danswer-ai/danswer CWE-639 7.5 - 2025-03-20
CVE-2024-7957 Arbitrary File Overwrite in danswer-ai/danswer — danswer-ai/danswer CWE-29 8.1 - 2025-03-20
CVE-2024-8065 CSRF in danswer-ai/danswer — danswer-ai/danswer CWE-352 8.1 - 2025-03-20
CVE-2025-0182 Denial of Service in danswer-ai/danswer — danswer-ai/danswer CWE-770 7.5 - 2025-03-20
CVE-2024-8028 Denial of Service in danswer-ai/danswer — danswer-ai/danswer CWE-770 7.5 - 2025-03-20
CVE-2024-7819 CORS Misconfiguration in danswer-ai/danswer — danswer-ai/danswer CWE-346 6.5 - 2025-03-20
CVE-2024-7779 ReDoS (Regular Expression Denial of Service) in danswer-ai/danswer — danswer-ai/danswer CWE-1333 7.5 - 2025-03-20

This page lists every published CVE security advisory associated with danswer-ai. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.