The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve arbitrary external content provided by an attacker, which can be used to proxy requests through The Librarian infrastructure. The vendor has fixed the vulnerability in all versions of TheLibrarian.
References
| Link | Resource |
|---|---|
| http://mindgard.ai/blog/thelibrarian-ios-ai-security- | Third Party Advisory |
| https://thelibrarian.io/ | Product |
Configurations
History
23 Jan 2026, 17:00
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| First Time |
Thelibrarian
Thelibrarian the Librarian |
|
| CPE | cpe:2.3:a:thelibrarian:the_librarian:-:*:*:*:*:*:*:* | |
| References | () http://mindgard.ai/blog/thelibrarian-ios-ai-security- - Third Party Advisory | |
| References | () https://thelibrarian.io/ - Product |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
16 Jan 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 13:16
Updated : 2026-01-23 17:00
NVD link : CVE-2026-0612
Mitre link : CVE-2026-0612
CVE.ORG link : CVE-2026-0612
JSON object : View
Products Affected
thelibrarian
- the_librarian
CWE
