Missing Authentication in PromtEngineer localGPT API Endpoint
CVE-2026-5000
What is CVE-2026-5000?
A vulnerability exists in the PromtEngineer localGPT API Endpoint, specifically in the LocalGPTHandler function of the backend/server.py file. This vulnerability relates to the manipulation of the argument BaseHTTPRequestHandler, leading to a scenario where authentication is not enforced. Consequently, this allows for potential unauthorized remote access to the API, creating significant security risks. The affected version includes all releases leading up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Despite efforts to contact the vendor prior to this disclosure, there has been no response regarding the issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
localGPT 4d41c7d1713b16b216d8e062e51a5dd88b20b054
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
