CVE-2026-5320 describes a missing authentication vulnerability affecting the Chat API Endpoint (/api/vanna/v2/) in vanna-ai vanna versions up to 2.0.2. This flaw carries a CVSS score of 7.3 (HIGH) and allows unauthenticated remote attackers to achieve low impacts on confidentiality, integrity, and availability with low attack complexity. An exploit for this vulnerability is publicly available and may be used, leading to its designation on the "Hot List: Active" despite minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vanna-Ai | Vanna | 2.0.0, 2.0.1, 2.0.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.