


Perceptive Security
SOC/SIEM Consultancy

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers u…
Published:
5 March 2026 at 23:00:00
Alert date:
6 March 2026 at 06:03:40
Source:
nvd.nist.gov
Security Tools, Emerging Technologies
OpenSift, an AI study tool for dataset analysis using semantic search and generative AI, contains a path injection vulnerability in versions prior to 1.6.3-alpha. The vulnerability exists in multiple storage helpers that use path construction patterns without proper base-directory containment enforcement. This creates path-injection risks in file read/write/delete operations when malicious path-like values are introduced. The issue has been patched in version 1.6.3-alpha with proper path validation controls.
Technical details
Mitigation steps:
Affected products:
OpenSift
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-28676
https://github.com/OpenSift/OpenSift/commit/1126e0a503876056a68a434e19f64158a5a4840b
https://github.com/OpenSift/OpenSift/commit/de99b9c
https://github.com/OpenSift/OpenSift/pull/67
https://github.com/OpenSift/OpenSift/releases/tag/v1.6.3-alpha
https://github.com/OpenSift/OpenSift/security/advisories/GHSA-ww4m-c7hv-2rqv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
