Arc53
Arc53 Docsgpt: vulnerabilities and CVEs
Arc53 Docsgpt has 6 published vulnerabilities, 4 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months4
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91201 | Medium (5.3) | 0.21% | — | Sep 14, 2026 | DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails… |
| CVE-2026-31020 | Critical (9.8) | 1.0% | — | Sep 4, 2026 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja… |
| CVE-2026-13483 | Low (1.3) | 0.13% | — | Jun 28, 2026 | A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the file application/security/encryption.py of the component Credential Storage. This manipulation causes… |
| CVE-2026-26015 | Critical (10) | 1.5% | — | Apr 29, 2026 | DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload… |
| CVE-2025-0868 | Critical (9.3) | 17% | — | Feb 20, 2025 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed… |
| CVE-2024-31451 | Medium (5.3) | 0.57% | — | Apr 16, 2024 | DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.py. This vulnerability is fixed in 0.8.1. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.