{"id":"CVE-2026-105049","details":"Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.","modified":"2026-10-06T02:30:23.896492337Z","published":"2026-10-02T22:14:36.181Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105049.json","cna_assigner":"mitre","cwe_ids":["CWE-306"]},"references":[{"type":"ADVISORY","url":"https://bishopfox.com/blog/zilliz-attu-2-6-5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105049.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105049"},{"type":"REPORT","url":"https://github.com/zilliztech/attu/issues/1028"},{"type":"PACKAGE","url":"https://github.com/zilliztech/attu"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zilliztech/attu","events":[{"introduced":"efa23c30f97cc23040796300a5f5c324df4291d6"},{"fixed":"21445b8ed8a607f281a45c988cf93f1c9ccef844"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"2.6.5"},{"fixed":"3.0.0"},{"introduced":"0"}]}}],"versions":["v3.0.0-beta.6","v3.0.0-beta.5","v3.0.0-beta.4","v3.0.0-beta.3","v3.0.0-beta.2","v3.0.0-beta.1","v2.6.5","v2.6.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105049.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"}]}