A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of the component Task Detail Endpoint. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://gist.github.com/YLChen-007/fe4b834144ad535d167507c2008d4011 | Exploit Third Party Advisory |
| https://vuldb.com/submit/784198 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/355384 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/355384/cti | Permissions Required VDB Entry |
Configurations
History
30 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tencent
Tencent ai-infra-guard |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:tencent:ai-infra-guard:4.0:*:*:*:*:*:*:* | |
| References | () https://gist.github.com/YLChen-007/fe4b834144ad535d167507c2008d4011 - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/submit/784198 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/355384 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/355384/cti - Permissions Required, VDB Entry |
05 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-05 18:16
Updated : 2026-04-30 21:16
NVD link : CVE-2026-5585
Mitre link : CVE-2026-5585
CVE.ORG link : CVE-2026-5585
JSON object : View
Products Affected
tencent
- ai-infra-guard
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo