GHSA-q76h-p6jh-9rw3

Suggest an improvement
Source
https://github.com/advisories/GHSA-q76h-p6jh-9rw3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q76h-p6jh-9rw3/GHSA-q76h-p6jh-9rw3.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-q76h-p6jh-9rw3
Aliases
Published
2026-06-08T03:47:24Z
Modified
2026-08-18T15:11:22Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 1.1 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
grepai Uses a Broken or Risky Cryptographic Algorithm
Details

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cwe_ids": [
        "CWE-327"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-28T20:56:44Z",
    "nvd_published_at": "2026-06-08T03:16:20Z",
    "severity": "LOW"
}
References

Affected packages

Go / github.com/yoanbernabeu/grepai

Package

Name
github.com/yoanbernabeu/grepai
View open source insights on deps.dev
Purl
pkg:golang/github.com/yoanbernabeu/grepai

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.35.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q76h-p6jh-9rw3/GHSA-q76h-p6jh-9rw3.json"