zilliztech/deep-searcher

zilliztech/deep-searcher

Releases5
Frequency3 weeks 10 hours
Last Release
Stars7.86K
Open Source Deep Research Alternative to Reason and Search on Private Data. Written in Python.

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM5.5 MEDIUM

A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.