openviking@0.1.17 vulnerabilities

An Agent-native context database

  • latest version

    0.2.6

  • latest non vulnerable version

  • first published

    1 months ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the openviking package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    openviking is an An Agent-native context database

    Affected versions of this package are vulnerable to Directory Traversal through the import process when handling .ovpack files. An attacker can overwrite or create arbitrary files outside the intended directory by crafting malicious ZIP archives containing traversal sequences, absolute paths, or drive prefixes in member names.

    How to fix Directory Traversal?

    Upgrade openviking to version 0.2.1 or higher.

    [,0.2.1)
    • C
    Missing Authentication for Critical Function

    openviking is an An Agent-native context database

    Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the omission of the root_api_key configuration. An attacker can gain unauthorized ROOT-level access by sending requests to protected endpoints without authentication headers, allowing full administrative control including account management, resource operations, and system configuration.

    How to fix Missing Authentication for Critical Function?

    Upgrade openviking to version 0.2.1.dev28 or higher.

    [,0.2.1.dev28)