CVE-2026-5321

MEDIUM

vanna-ai vanna FastAPI/Flask Server cross-domain policy

Title source: cna
STIX 2.1

Description

A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Vdb Entry vdb-entry
VDB-354653 | vanna-ai vanna FastAPI/Flask Server cross-domain policy
https://vuldb.com/vuln/354653
Signature, Permissions Required signature permissions-required
VDB-354653 | CTI Indicators (IOB, IOC)
https://vuldb.com/vuln/354653/cti
Third Party Advisory third-party-advisory
Submit #780729 | vanna-ai vanna 2.0.2 CORS Origin Reflection with Credentials
https://vuldb.com/submit/780729
Exploit exploit issue-tracking
https://github.com/August829/CVEP/issues/14

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-346 CWE-942
Status published
Products (3)
vanna-ai/vanna 2.0.0
vanna-ai/vanna 2.0.1
vanna-ai/vanna 2.0.2
Published Apr 02, 2026
Tracked Since Apr 02, 2026