
zilliztech/deep-searcher
Releases5
Frequency3 weeks 10 hours
Last Release
Stars7.86K
Open Source Deep Research Alternative to Reason and Search on Private Data. Written in Python.
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.4 MEDIUM | 5.5 MEDIUM | ||
A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance. | |||