Home

Description

The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.

PUBLISHED Reserved 2026-01-05 | Published 2026-01-16 | Updated 2026-01-16 | Assigner certcc

Problem types

CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere

Product status

Any version
affected

References

mindgard.ai/blog/thelibrarian-ios-ai-security-disclosure

thelibrarian.io/

cve.org (CVE-2026-0613)

nvd.nist.gov (CVE-2026-0613)

Download JSON