PatchSiren

Volcengine CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL volcengine CVE published 2026-04-17

CVE-2026-40525

OpenViking prior to version 0.3.9 contains a critical authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface. This vulnerability allows remote attackers with network access to invoke privileged bot-control functionality without a valid X-API-Key header when the api_key configuration value is unset or empty. The vulnerability enables attackers to submit attacker-controlled prompts, [truncated]

MEDIUM Volcengine CVE published 2026-04-07

CVE-2026-22680

CVE-2026-22680 is a missing authorization vulnerability in OpenViking versions prior to 0.3.3. The vulnerability allows unauthorized attackers to enumerate or retrieve background task metadata created by other users, potentially causing cross-tenant interference in multi-tenant deployments. This issue affects users of OpenViking and requires immediate attention to prevent exploitation.

MEDIUM Volcengine CVE published 2026-04-01

CVE-2026-34999

CVE-2026-34999 is a missing authentication vulnerability in OpenViking versions 0.2.5 to 0.2.13. Remote unauthenticated attackers can access protected bot proxy functionality. Fixed in version 0.2.14. This issue allows attackers to bypass authentication checks and interact directly with the upstream bot backend through the OpenViking proxy without valid credentials.

HIGH Volcengine CVE published 2026-03-03

CVE-2026-28518

CVE-2026-28518 is a path traversal vulnerability in OpenViking versions 0.2.1 and prior. The vulnerability allows attackers to write files outside the intended import directory by crafting malicious ZIP archives with traversal sequences, absolute paths, or drive prefixes in member names. The vulnerability was fixed in commit 46b3e76. This issue affects users of OpenViking versions 0.2.1 and prior, who sho [truncated]