The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.
References
| Link | Resource |
|---|---|
| https://mindgard.ai/blog/thelibrarian-ios-ai-security-disclosure | Third Party Advisory |
| https://thelibrarian.io/ | Product |
Configurations
History
23 Jan 2026, 17:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Thelibrarian
Thelibrarian the Librarian |
|
| CWE | CWE-918 | |
| References | () https://mindgard.ai/blog/thelibrarian-ios-ai-security-disclosure - Third Party Advisory | |
| References | () https://thelibrarian.io/ - Product | |
| CPE | cpe:2.3:a:thelibrarian:the_librarian:-:*:*:*:*:*:*:* |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
16 Jan 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 13:16
Updated : 2026-01-23 17:00
NVD link : CVE-2026-0613
Mitre link : CVE-2026-0613
CVE.ORG link : CVE-2026-0613
JSON object : View
Products Affected
thelibrarian
- the_librarian
CWE
CWE-918
Server-Side Request Forgery (SSRF)
