Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 28 Feb 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lintsinghua:deepaudit:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lintsinghua
Lintsinghua deepaudit |
|
| Vendors & Products |
Lintsinghua
Lintsinghua deepaudit |
Fri, 06 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepAudit is a multi-agent system for code vulnerability discovery. In 3.0.4 and earlier, there is an improper access control vulnerability in the /api/v1/users/ endpoint allows any authenticated user to enumerate all users in the system and retrieve sensitive information including email addresses, phone numbers, full names, and role information. | |
| Title | DeepAudit Affected by User Enumeration via Broken Access Control | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T20:50:17.216Z
Reserved: 2026-02-05T16:48:00.427Z
Link: CVE-2026-25729
Updated: 2026-02-06T20:49:02.118Z
Status : Analyzed
Published: 2026-02-06T21:16:19.313
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-25729
No data.
OpenCVE Enrichment
Updated: 2026-04-18T13:30:45Z