Impact
The vulnerability is located in the SplitTokens/ShuntingYard routine of the Filter Parser in engine/query/expr/expr.cpp of epsilla-cloud vectordb. An improper check for unusual conditions allows manipulation of filter expressions that could alter the expected parsing behavior. The flaw does not provide a documented remote exploitation path; it requires local access to the system running vectordb, but because the parser logic can be altered it may lead to unintended data access or the execution of untrusted code if the attacker can supply specially crafted expressions.
Affected Systems
epsilla‑cloud vectordb versions up to 0.3.18 (commit df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a) are affected. All releases before 0.3.19 contain this flaw.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available, suggesting there is limited evidence of real-world exploitation. The vulnerability requires local interaction and has not appeared in the CISA KEV catalog. Consequently, the risk to untrusted remote users is low, but an attacker with local privileges could manipulate filter expressions until a vendor fix is issued.
OpenCVE Enrichment