pipeshub CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

pipeshub vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to pipeshub, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-67506 PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by uploading payload to os.path.join(tmpdir, file.filename) without normalizing the filename. An attacker can submit a crafted filename containing ../ sequences to write arbitrary files anywhere the service account has perm [email protected] 9.8 1.61% 2025-12-10 2026-03-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence