PT-2026-23642 · Openshift · Openshift

·

CVE-2026-28675

·

Published

2026-03-06

·

Updated

2026-03-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSift versions prior to 1.6.3-alpha
Description OpenSift is an AI study tool that uses semantic search and generative AI to analyze large datasets. Prior to version 1.6.3-alpha, certain API endpoints returned raw exception strings to clients, potentially exposing sensitive implementation details. Additionally, login token material was exposed in the user interface and token rotation output. The vulnerable endpoints include those that handle exceptions and token management. The exposed token material includes information related to user authentication. The token is exposed in UI responses and token rotation output.
Recommendations Update to version 1.6.3-alpha or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28675
GHSA-667G-RVCJ-W976

Affected Products

Openshift