VDB

CVE-2026-0613

CVE-2026-0613 PUBLISHED CVSS 8.699999809265137 HIGH

The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.

EPSS 0.02% · 4.4th percentile

Risk Scores

CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:L/SA:N
EPSS Score
0.02%
4.4th percentile

Affected Products

VendorProductVersions
thelibrarianthe_librarian
TheLibrarianTheLibrarian.io0, 0

Timeline

  • Jan 16, 2026 CVE Published
  • Jan 16, 2026 PoC Published
  • Jan 17, 2026 EPSS Score
  • Jan 17, 2026 PoC Published
  • Jan 20, 2026 EPSS Score
  • Jan 23, 2026 EPSS Score
  • Jan 23, 2026 CVE Updated
  • Jan 26, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Feb 3, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›