cheshire-cat-ai has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.9 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.9
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
cheshire-cat-ai vulnerabilities
CVEs affecting cheshire-cat-ai, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-90579High· 7.3PoCA vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2
A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing a…
▾ Midnightcheshire-cat-ai · Cheshire Cat AIEPSS 0.65%via NVD
CVE-2026-85093Medium· 6.5PoCCheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conver…
▾ Twilightcheshire-cat-ai · coreEPSS 0.41%via NVD