CVE-2026-65700 is a critical path traversal vulnerability in h2oGPT's OpenAI-compatible files API. The vulnerability allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The get_user_dir function in openai_server/backend_utils.py uses the bearer token string unsanitized as a path component [truncated]
CVE-2026-8750 describes an information-disclosure issue in h2oai h2o-3, affecting the importFiles function in h2o-core/src/main/java/water/persist/PersistNFS.java as part of the ImportFile API. The CVE record indicates the issue can be triggered remotely and that a public exploit is available. Based on the published CVSS vector, the primary impact is confidentiality loss rather than integrity or availability impact.