Opensift is a narrowly scoped platform product with a modestly represented vulnerability profile that reflects its role in request-handling and data-processing contexts. Its recurring weakness classes—server-side request forgery, race conditions, sensitive-information disclosure, and output-encoding issues—align with the architectural demands of a system that mediates external requests and manages shared resources. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensift over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28676HIGH OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers used path constructio | Mar 6, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27169HIGH OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat t | Feb 21, 2026 | 8.9 | 29 | NO | NO |
CVE-2026-28677HIGH OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline accepted user-controll | Mar 6, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-27170HIGH OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest allows overly permissive serve | Feb 21, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-27189MEDIUM OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below, use non-atomic and insufficiently synchroniz | Feb 21, 2026 | 5.8 | 21 | NO | NO |
CVE-2026-28675MEDIUM OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints returned raw exception strings | Mar 6, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensift.
Media articles that mention a CVE ID that affects a product developed by Opensift — matched by CVE ID, not by vendor name.