PT-2026-23642 · Openshift · Openshift

Mdavis

·

Published

2026-03-06

·

Updated

2026-03-06

·

CVE-2026-28675

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSift versions prior to 1.6.3-alpha
Description OpenSift is an AI study tool that uses semantic search and generative AI to analyze large datasets. Prior to version 1.6.3-alpha, certain API endpoints returned raw exception strings to clients, potentially exposing sensitive implementation details. Additionally, login token material was exposed in the user interface and token rotation output. The vulnerable endpoints include those that handle exceptions and token management. The exposed token material includes information related to user authentication. The token is exposed in UI responses and token rotation output.
Recommendations Update to version 1.6.3-alpha or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-28675
GHSA-667G-RVCJ-W976

Affected Products

Openshift