A AegiFlow
LOWCVSS 2.1EPSS 0.3%

CVE-2026-11466

CVE-2026-11466 updated by NVD

Published
2026-06-08
Modified
2026-07-28
EPSS percentile
17%
Sources
github-advisory, nvd

Summary

A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIdeepsearcher

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.