{"id":"CVE-2026-11481","aliases":["GHSA-q76h-p6jh-9rw3","GO-2026-6128"],"url":"https://o3.security/vulnerability/CVE-2026-11481","summary":"yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash","details":"A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.","published":"2026-06-08T02:45:11.546Z","modified":"2026-09-09T18:26:43.544331463Z","cvss":null,"epss":{"score":0.00082,"percentile":0.00246,"asOf":"2026-09-02"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/yoanbernabeu/grepai","fixedVersion":null}],"fix":{"url":"https://github.com/yoanbernabeu/grepai/pull/250","label":"yoanbernabeu/grepai#250"},"references":[{"type":"WEB","url":"https://github.com/yoanbernabeu/grepai/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11481.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11481"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-11481"},{"type":"ADVISORY","url":"https://vuldb.com/submit/833997"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/369101"},{"type":"REPORT","url":"https://github.com/yoanbernabeu/grepai/issues/249"},{"type":"REPORT","url":"https://vuldb.com/vuln/369101/cti"},{"type":"FIX","url":"https://github.com/yoanbernabeu/grepai/pull/250"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T18:26:43.544331463Z"}}