---
id: CVE-2026-11481
aliases:
  - GHSA-q76h-p6jh-9rw3
title: grepai Uses a Broken or Risky Cryptographic Algorithm
summary: grepai Uses a Broken or Risky Cryptographic Algorithm
severity: low
cvss: 2.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: yoanbernabeu
product: github.com/yoanbernabeu/grepai
ecosystem: go
affected:
  - github.com/yoanbernabeu/grepai <= 0.35.0
published: '2026-06-08'
updated: '2026-07-28'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-q76h-p6jh-9rw3'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11481'
  - url: 'https://github.com/yoanbernabeu/grepai/issues/249'
  - url: 'https://github.com/yoanbernabeu/grepai/pull/250'
  - url: 'https://github.com/yoanbernabeu/grepai'
  - url: 'https://vuldb.com/cve/CVE-2026-11481'
  - url: 'https://vuldb.com/submit/833997'
  - url: 'https://vuldb.com/vuln/369101'
  - url: 'https://vuldb.com/vuln/369101/cti'
tags:
  - osv
  - go
epss: 0.00082
epssPercentile: 0.00266
ingestedAt: '2026-07-29T19:09:37.649Z'
---

## Overview

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

## Affected packages

- `github.com/yoanbernabeu/grepai <= 0.35.0`

## Remediation

Refer to the advisory for the patched release.
