GHSA-6h35-9p2w-3j3r

Suggest an improvement
Source
https://github.com/advisories/GHSA-6h35-9p2w-3j3r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6h35-9p2w-3j3r/GHSA-6h35-9p2w-3j3r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6h35-9p2w-3j3r
Aliases
Published
2026-06-08T03:47:24Z
Modified
2026-08-18T15:10:54Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
grepai Uses a Broken or Risky Cryptographic Algorithm
Details

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cwe_ids":  [
        "CWE-327"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-28T20:54:00Z",
    "nvd_published_at":  "2026-06-08T03:16:20Z",
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/yoanbernabeu/grepai

Package

Name
github.com/yoanbernabeu/grepai
View open source insights on deps.dev
Purl
pkg:golang/github.com/yoanbernabeu/grepai

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.35.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6h35-9p2w-3j3r/GHSA-6h35-9p2w-3j3r.json"