CVE-2026-14630

Source
https://cve.org/CVERecord?id=CVE-2026-14630
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14630.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14630
Published
2026-07-04T14:00:10.026Z
Modified
2026-08-12T03:51:47.293200057Z
Severity
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
Details

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function getconversationhistory of the file 08agenticsystem/memory/langchain/code/smartcustomerservice.py of the component Memory Recall Handler. The manipulation leads to use of weak hash. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is f57277fdd9ba373ace72d83c272023ec67f720d6. It is suggested to install a patch to address this issue. The project confirms (translated from Chinese): "We now require session ownership verification in methods such as username, sessionowner, etc., and we've chat()changed the generation of sessionowner to include verified user identity and security context metadata."

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14630.json",
    "cwe_ids": [
        "CWE-327",
        "CWE-328"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/forceinjection/ai-fundamentals

Affected ranges

Type
GIT
Repo
https://github.com/forceinjection/ai-fundamentals
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.0"
        },
        {
            "last_affected": "2.0"
        },
        {
            "introduced": "3.0"
        },
        {
            "last_affected": "3.0"
        }
    ]
}

Affected versions

2.*
2.0
3.*
3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14630.json"