CVE-2026-11481
LOWyoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
Title source: cnaDescription
A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
References (7)
Core 7
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-369101 | yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
https://vuldb.com/vuln/369101
Signature, Permissions Required signature
permissions-required
VDB-369101 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/369101/cti
Third Party Advisory third-party-advisory
CVE-2026-11481 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-11481
Third Party Advisory third-party-advisory
Submit #833997 | yoanbernabeu grepai v0.35.0-1-gf6dbf8d Cache Poisoning
https://vuldb.com/submit/833997
Exploit exploit
issue-tracking
https://github.com/yoanbernabeu/grepai/issues/249
Patch issue-tracking
patch
https://github.com/yoanbernabeu/grepai/pull/250
Product product
https://github.com/yoanbernabeu/grepai/
Scores
CVSS v3
2.5
EPSS
0.0008
EPSS Percentile
0.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-327
CWE-328
Status
published
Products (35)
yoanbernabeu/grepai
0.1
yoanbernabeu/grepai
0.10
yoanbernabeu/grepai
0.11
yoanbernabeu/grepai
0.12
yoanbernabeu/grepai
0.13
yoanbernabeu/grepai
0.14
yoanbernabeu/grepai
0.15
yoanbernabeu/grepai
0.16
yoanbernabeu/grepai
0.17
yoanbernabeu/grepai
0.18
... and 25 more
Published
Jun 08, 2026
Tracked Since
Jun 08, 2026