Database/AI/ML frameworks & serving
Qdrant (`/logger`): Append to arbitrary files via the logger endpoint
CVSS 8.5CVE-2026-25628AI/ML frameworks & servingcurated
Impact
Append to arbitrary files via the logger endpoint
Who can reach it
Network user of the Qdrant API
What to do
Upgrade to 1.16.0+
References
Related entries
- llama.cpp llama-server: crafted sampler parameter triggers out-of-bounds read and unauthenticated crashCVE-2026-43628 · llama.cpp llama-server (DRY sampler, /v1/completions and /v1/chat/completions)High
- NVIDIA OpenShell Sandbox: path traversal bypasses L7 REST network policy, exposing blocked endpointsCVE-2026-65092 · NVIDIA OpenShell Sandbox for Linux (L7 REST network policy enforcement)High
- Darknet: integer overflow in convolutional layer sizing yields a heap overflow from a crafted .cfgCVE-2026-72852 · hank-ai/darknet convolutional layer (.cfg model definition parsing)High
- vLLM: remote processor code executes even when trust_remote_code is falseCVE-2026-90553 · vLLM (LlavaOnevision2 processor loader)High
- skops (`Card.get_model`): Model card loading has no trusted-types checkCVE-2025-54886 · skops (`Card.get_model`)High
- mcp-shell: allowlist validates only the first token, so /bin/bash -c runs any commandCVE-2026-55581 · mcp-shell (security.go command allowlist, /bin/bash -c handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.