PatchSiren

arc53 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM arc53 CVE published 2026-09-14

CVE-2026-91201

CVE-2026-91201 is a medium-severity vulnerability in DocsGPT through 0.20.0, where OAuth connector session tokens are posted to a wildcard target origin in the callback-status endpoint without validating sender origin. This allows attackers to obtain session tokens and provider account emails by acting as window.opener during OAuth authorization. Defenders should assess their exposure and prioritize verif [truncated]

LOW arc53 CVE published 2026-06-28

CVE-2026-13483

CVE-2026-13483 is a vulnerability in arc53 DocsGPT versions up to 0.18.0. The issue lies in the encrypt_credentials function within the application/security/encryption.py file, which is part of the Credential Storage component. This vulnerability leads to insufficient verification of data authenticity. An attacker can initiate the attack remotely, but the complexity of the attack is high and its exploitab [truncated]