« Back to list

Arc53

Arc53 Docsgpt: vulnerabilities and CVEs

Arc53 Docsgpt has 6 published vulnerabilities, 4 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months4
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-91201Medium (5.3)0.21%—Sep 14, 2026
DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails…
CVE-2026-31020Critical (9.8)1.0%—Sep 4, 2026
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja…
CVE-2026-13483Low (1.3)0.13%—Jun 28, 2026
A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component Credential Storage. This manipulation causes…
CVE-2026-26015Critical (10)1.5%—Apr 29, 2026
DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload…
CVE-2025-0868Critical (9.3)17%—Feb 20, 2025
A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed…
CVE-2024-31451Medium (5.3)0.57%—Apr 16, 2024
DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.