Impact
The vulnerability lies in the _deduplicate_results function of BettaFish’s InsightEngine Search‑Result Deduplication results, allowing an attacker to craft input that makes distinct results appear identical. This manipulation can lead to incorrect data presentation or the acceptance of duplicated entries, potentially compromising data integrity. The flaw is exploitable remotely, as the execution path is reachable through the exposed Deduplication endpoint.
Affected Systems
All deployments of 666ghj BettaFish version 1.2.1 or earlier contain the vulnerable code path. The issue is present in the InsightEngine component and affects any server instance that exposes the Deduplication service without additional restrictions.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% shows that exploitation attempts are currently rare. The vulnerability is not yet listed in CISA’s KEV catalog exposed Deduplication endpoint. Until the pending fix is merged, the risk remains moderate but could be mitigated by limiting external access or applying a temporary patch.
OpenCVE Enrichment