VDB

CVE-2026-0612

CVE-2026-0612 PUBLISHED CVSS 8.699999809265137 HIGH

The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.

EPSS 0.02% · 4.2th percentile

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.02%
4.2th percentile

Affected Products

VendorProductVersions
TheLibrarianTheLibrarian.io0, 0
thelibrarianthe_librarian

Timeline

  • Jan 16, 2026 CVE Published
  • Jan 16, 2026 PoC Published
  • Jan 16, 2026 PoC Published
  • Jan 17, 2026 EPSS Score
  • Jan 17, 2026 CVE Updated
  • Jan 20, 2026 EPSS Score
  • Jan 23, 2026 EPSS Score
  • Jan 26, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Feb 3, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›