top of page
perceptive_background_267k.jpg

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers u…

Published:

5 maart 2026 om 23:00:00

Alert date:

6 maart 2026 om 06:03:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Emerging Technologies

OpenSift, an AI study tool for dataset analysis using semantic search and generative AI, contains a path injection vulnerability in versions prior to 1.6.3-alpha. The vulnerability exists in multiple storage helpers that use path construction patterns without proper base-directory containment enforcement. This creates path-injection risks in file read/write/delete operations when malicious path-like values are introduced. The issue has been patched in version 1.6.3-alpha with proper path validation controls.

Technical details

Mitigation steps:

Affected products:

OpenSift

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page