{"id":"CVE-2026-14738","summary":"exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash","details":"A security flaw has been discovered in exo-explore exo up to 1.0.71. Affected is the function _image_cache_key of the file src/exo/worker/engines/mlx/vision.py of the component Vision Feature Cache. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. The pull request to fix this issue awaits acceptance.","modified":"2026-08-12T03:51:12.496303889Z","published":"2026-07-05T10:15:09.187Z","database_specific":{"cwe_ids":["CWE-327","CWE-328"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14738.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.0.0"},{"last_affected":"1.0.0"},{"introduced":"1.0.1"},{"last_affected":"1.0.1"},{"introduced":"1.0.2"},{"last_affected":"1.0.2"},{"introduced":"1.0.3"},{"last_affected":"1.0.3"},{"introduced":"1.0.4"},{"last_affected":"1.0.4"},{"introduced":"1.0.5"},{"last_affected":"1.0.5"},{"introduced":"1.0.6"},{"last_affected":"1.0.6"},{"introduced":"1.0.7"},{"last_affected":"1.0.7"},{"introduced":"1.0.8"},{"last_affected":"1.0.8"},{"introduced":"1.0.9"},{"last_affected":"1.0.9"},{"introduced":"1.0.10"},{"last_affected":"1.0.10"},{"introduced":"1.0.11"},{"last_affected":"1.0.11"},{"introduced":"1.0.12"},{"last_affected":"1.0.12"},{"introduced":"1.0.13"},{"last_affected":"1.0.13"},{"introduced":"1.0.14"},{"last_affected":"1.0.14"},{"introduced":"1.0.15"},{"last_affected":"1.0.15"},{"introduced":"1.0.16"},{"last_affected":"1.0.16"},{"introduced":"1.0.17"},{"last_affected":"1.0.17"},{"introduced":"1.0.18"},{"last_affected":"1.0.18"},{"introduced":"1.0.19"},{"last_affected":"1.0.19"},{"introduced":"1.0.20"},{"last_affected":"1.0.20"},{"introduced":"1.0.21"},{"last_affected":"1.0.21"},{"introduced":"1.0.22"},{"last_affected":"1.0.22"},{"introduced":"1.0.23"},{"last_affected":"1.0.23"},{"introduced":"1.0.24"},{"last_affected":"1.0.24"},{"introduced":"1.0.25"},{"last_affected":"1.0.25"},{"introduced":"1.0.26"},{"last_affected":"1.0.26"},{"introduced":"1.0.27"},{"last_affected":"1.0.27"},{"introduced":"1.0.28"},{"last_affected":"1.0.28"},{"introduced":"1.0.29"},{"last_affected":"1.0.29"},{"introduced":"1.0.30"},{"last_affected":"1.0.30"},{"introduced":"1.0.31"},{"last_affected":"1.0.31"},{"introduced":"1.0.32"},{"last_affected":"1.0.32"},{"introduced":"1.0.33"},{"last_affected":"1.0.33"},{"introduced":"1.0.34"},{"last_affected":"1.0.34"},{"introduced":"1.0.35"},{"last_affected":"1.0.35"},{"introduced":"1.0.36"},{"last_affected":"1.0.36"},{"introduced":"1.0.37"},{"last_affected":"1.0.37"},{"introduced":"1.0.38"},{"last_affected":"1.0.38"},{"introduced":"1.0.39"},{"last_affected":"1.0.39"},{"introduced":"1.0.40"},{"last_affected":"1.0.40"},{"introduced":"1.0.41"},{"last_affected":"1.0.41"},{"introduced":"1.0.42"},{"last_affected":"1.0.42"},{"introduced":"1.0.43"},{"last_affected":"1.0.43"},{"introduced":"1.0.44"},{"last_affected":"1.0.44"},{"introduced":"1.0.45"},{"last_affected":"1.0.45"},{"introduced":"1.0.46"},{"last_affected":"1.0.46"},{"introduced":"1.0.47"},{"last_affected":"1.0.47"},{"introduced":"1.0.48"},{"last_affected":"1.0.48"},{"introduced":"1.0.49"},{"last_affected":"1.0.49"},{"introduced":"1.0.50"},{"last_affected":"1.0.50"},{"introduced":"1.0.51"},{"last_affected":"1.0.51"},{"introduced":"1.0.52"},{"last_affected":"1.0.52"},{"introduced":"1.0.53"},{"last_affected":"1.0.53"},{"introduced":"1.0.54"},{"last_affected":"1.0.54"},{"introduced":"1.0.55"},{"last_affected":"1.0.55"},{"introduced":"1.0.56"},{"last_affected":"1.0.56"},{"introduced":"1.0.57"},{"last_affected":"1.0.57"},{"introduced":"1.0.58"},{"last_affected":"1.0.58"},{"introduced":"1.0.59"},{"last_affected":"1.0.59"},{"introduced":"1.0.60"},{"last_affected":"1.0.60"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/exo-explore/exo/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14738.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14738"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-14738"},{"type":"ADVISORY","url":"https://vuldb.com/submit/848737"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/376321"},{"type":"REPORT","url":"https://github.com/exo-explore/exo/issues/2151"},{"type":"REPORT","url":"https://vuldb.com/vuln/376321/cti"},{"type":"FIX","url":"https://github.com/exo-explore/exo/pull/2152"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/exo-explore/exo","events":[{"introduced":"4759b09d4c81ceabed89a8ae1b4c8903a0e29a01"},{"last_affected":"fd707de30b42db4211d15da96b9052e1dc280ed1"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.0.61"},{"last_affected":"1.0.61"},{"introduced":"1.0.62"},{"last_affected":"1.0.62"},{"introduced":"1.0.63"},{"last_affected":"1.0.63"},{"introduced":"1.0.64"},{"last_affected":"1.0.64"},{"introduced":"1.0.65"},{"last_affected":"1.0.65"},{"introduced":"1.0.66"},{"last_affected":"1.0.66"},{"introduced":"1.0.67"},{"last_affected":"1.0.67"},{"introduced":"1.0.68"},{"last_affected":"1.0.68"},{"introduced":"1.0.69"},{"last_affected":"1.0.69"},{"introduced":"1.0.70"},{"last_affected":"1.0.70"},{"introduced":"1.0.71"},{"last_affected":"1.0.71"}]}}],"versions":["1.0.61","1.0.62","1.0.63","1.0.64","1.0.65","1.0.66","1.0.67","1.0.68","1.0.69","1.0.70","1.0.71","v1.0.71","v1.0.70","v1.0.69","v1.0.68","test-screenshots-tmp","gh-screenshot-assets","pr-1465-screenshots","v1.0.63","v1.0.62","v1.0.61"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14738.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}