Liquid-co has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.8 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-103398High· 8.1OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler45CVE-2026-103397Medium· 5.6OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field31
Liquid-co vulnerabilities
CVEs affecting Liquid-co, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-103398High· 8.1OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest…
▾ TwilightLiquid-co · OpenSavevia NVD
CVE-2026-103397Medium· 5.6OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read p…
▾ SunlitLiquid-co · OpenSavevia NVD