PT-2026-25015 · Git+2 · Hyperterse
Samrith-S
·
Publicado
2026-03-12
·
Atualizado
2026-03-12
·
CVE-2026-31841
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hyperterse versions prior to 2.2.0
Description
Hyperterse is a framework designed for building AI-ready backend surfaces. Prior to version 2.2.0, the search tool permitted Large Language Models (LLMs) to search for tools using natural language. During the return of results, Hyperterse inadvertently exposed raw SQL queries, revealing statements intended for internal execution and shielded from public display. The
search tool allows LLMs to search for tools using natural language. The exposed queries originated from database operations specified by users for tools to execute. The vulnerable components include the search tool and the underlying database query mechanisms.Recommendations
Versions prior to 2.2.0 should be updated to version 2.2.0 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hyperterse