PatchSiren

ItzCrazyKns CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ItzCrazyKns CVE published 2026-05-24

CVE-2026-9372

A server-side request forgery (SSRF) vulnerability exists in ItzCrazyKns Vane up to version 1.12.1, specifically within the Model Provider API component located at src/app/api/providers/route.ts. The vulnerability stems from improper validation of the baseURL argument, allowing remote attackers to manipulate this parameter to induce unauthorized server-side requests. The issue was reported to the project [truncated]

LOW ItzCrazyKns CVE published 2026-05-24

CVE-2026-9371

A missing authentication vulnerability in ItzCrazyKns Vane up to version 1.12.1 allows remote attackers to access API functionality without proper credentials. The vulnerability resides in the route.ts file of the API component. While the CVSS 4.0 score of 2.9 (LOW) reflects limited impact potential, the public disclosure of exploit details and the planned but unimplemented basic authentication indicate a [truncated]