ZeroHour

CVE-2026-0612

CVSS 3.1
7.5 high
EPSS
<1%p29
Published
()
Modified
Description

The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.

Vendors
thelibrarian
Products
the librarian
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news