Impact
The vulnerability is present in volcengine OpenViking up to version 0.3.21 and is located in the str_to_uint64 function used for handling primary‑key labels in Local VectorDB. By manipulating the ID argument, an attacker can bypass authentication checks, potentially allowing forged or altered keys to be accepted. The CVSS score of 2.3 reflects the modest impact when the functionality is limited to a single dataset. The description indicates that the attack may be launched remotely and is considered highly complex with a difficult exploitability.
Affected Systems
All installations of volcengine OpenViking prior to version 0.3.21, specifically those using the Local VectorDB component. The affected vendor is volcengine and the product affected is OpenViking.
Risk and Exploitability
With a CVSS score of 2.3 and no EPSS data available, the exploitation likelihood remains unclear. The vulnerability is not listed in CISA KEV, reducing the alert level. The likely attack vector is remote, but the description emphasizes that practical exploitation is difficult. The weakness is categorized as CWE‑345, indicating insufficient data authentication.
OpenCVE Enrichment