VulnSea

ai_assist_for_customer vulnerabilities

CVEs whose affected-version data names the ai_assist_for_customer package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-57476Medium· 4.8
2mo ago

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus

Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI…

Sunlitdeloitte · ai_assist_for_customerEPSS 0.44%via NVD
CVE-2026-57475Medium· 5.3
2mo ago

Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration

Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 202…

Sunlitdeloitte · ai_assist_for_customerEPSS 0.60%via NVD
CVE-2026-57474Medium· 5.3
2mo ago

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests

Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Ass…

Sunlitdeloitte · ai_assist_for_customerEPSS 0.51%via NVD
ai_assist_for_customer vulnerabilities (CVEs) · VulnSea