agent-coderag vulnerabilities
CVEs whose affected-version data names the agent-coderag package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-57586High· 8.6CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/mana…
▾ Twilightnaranor · agent-coderagEPSS 0.15%via NVD
GHSA-wg5p-8h9p-3mr7High· 8.6agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
▾ Twilightagent-coderag · agent-coderagvia GHSA