Missing Authentication in PromtEngineer localGPT API Endpoint
CVE-2026-5000

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 March 2026

What is CVE-2026-5000?

A vulnerability exists in the PromtEngineer localGPT API Endpoint, specifically in the LocalGPTHandler function of the backend/server.py file. This vulnerability relates to the manipulation of the argument BaseHTTPRequestHandler, leading to a scenario where authentication is not enforced. Consequently, this allows for potential unauthorized remote access to the API, creating significant security risks. The affected version includes all releases leading up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Despite efforts to contact the vendor prior to this disclosure, there has been no response regarding the issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

localGPT 4d41c7d1713b16b216d8e062e51a5dd88b20b054

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu_Bao (VulDB User)
VulDB
.