CVE-2026-11479 PUBLISHED

yoanbernabeu grepai Qdrant Backend chunker.go weak hash

Assigner: VulDB
Reserved: 07.06.2026 Published: 08.06.2026 Updated: 08.06.2026

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 2.3

Product Status

Vendor yoanbernabeu
Product grepai
Versions
  • Version 0.35.0 is affected

Credits

  • Dem000 (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Use of Weak Hash CWE
  • Risky Cryptographic Algorithm CWE