CVE-2026-5803
Last modified
CVE-2026-5803 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulation of the argument Query results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is named 54f8f50f43af97c334a881af7b021e84b5b8310f. It is suggested to install a patch to address this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-5803?
How severe is CVE-2026-5803?
How do I fix CVE-2026-5803?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58024Exposure of Sensitive Information to an Unauthorized Actor v…5.7
- CVE-2026-58025Deserialization of untrusted data vulnerability in Wikimedia…9.8
- CVE-2026-58026Exposure of Sensitive Information to an Unauthorized Actor v…5.7
- CVE-2026-58027Exposure of Sensitive Information to an Unauthorized Actor v…6.5
- CVE-2026-58028Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-58029Vulnerability in Wikimedia Foundation MediaWiki. This vuln…6.5
- CVE-2026-58030Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-58031Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-58032Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-58033Exposure of Sensitive Information to an Unauthorized Actor v…6.5
- CVE-2026-58034Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2026-58035Improper Neutralization of Input During Web Page Generation …4.8
Are you affected by CVE-2026-5803?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
