Description
The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.
Published: 2026-01-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Leakage
Action: Patch Immediately
AI Analysis

Impact

The Librarian contains an information‑leakage vulnerability linked to its web_fetch tool. The tool allows an attacker to request any external URL, causing the application to fetch the content and potentially expose it. This can be used to proxy arbitrary requests through the Librarian’s infrastructure, effectively turning the service into a relay for malicious traffic or enabling the retrieval of sensitive information that shouldn’t be publicly accessed. The flaw represents an information exposure weakness that could expose data the application is not intended to disclose.

Affected Systems

The L ibrarian.io product, known simply as The Librarian, is impacted. All releases prior to the vendor‑provided fix are vulnerable, and the vendor has released a patch that removes the flaw from every current version of the application.

Risk and Exploitability

The CVSS base score of 7.5 places the weakness in the high‑severity range. The EPSS score of less than 1% indicates a low likelihood of exploitation at present, and it is not currently listed in the CISA KEV catalog. The most likely attack route is a network‑based request: an attacker can supply a crafted URL to the web_fetch tool and cause The Librarian to retrieve arbitrary content, thereby using the system as a proxy or leaking external data. No privileged execution is required on the target system.

Generated by OpenCVE AI on April 18, 2026 at 19:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch that addresses the web_fetch vulnerability.
  • If an immediate upgrade is not possible, disable or restrict the web_fetch tool so that it cannot retrieve external content.
  • Monitor outbound traffic from The Librarian for unusual or unexpected requests that may indicate abuse.

Generated by OpenCVE AI on April 18, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-918

Fri, 23 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Thelibrarian the Librarian
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:thelibrarian:the_librarian:-:*:*:*:*:*:*:*
Vendors & Products Thelibrarian the Librarian

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Thelibrarian
Thelibrarian thelibrarian
Vendors & Products Thelibrarian
Thelibrarian thelibrarian

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 13:00:00 +0000

Type Values Removed Values Added
Description The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.
Title CVE-2026-0612
References

Subscriptions

Thelibrarian The Librarian Thelibrarian
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-01-16T21:42:52.062Z

Reserved: 2026-01-05T17:39:25.528Z

Link: CVE-2026-0612

cve-icon Vulnrichment

Updated: 2026-01-16T21:42:37.828Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-16T13:16:11.677

Modified: 2026-01-23T17:00:47.540

Link: CVE-2026-0612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:15:10Z