MEDIUM5.3
PYSEC-2026-2855
OpenViking contains a missing authorization vulnerability in the task polling endpoints
Quick fix
PYSEC-2026-2855 — openviking: upgrade to the fixed version with the command below.
pip install --upgrade 'openviking>=0.3.3'Details
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes without authentication to expose task type, task status, resource identifiers, archive URIs, result payloads, and error information, potentially causing cross-tenant interference in multi-tenant deployments.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-22680[ADVISORY]
- https://github.com/volcengine/OpenViking/pull/1182[WEB]
- https://github.com/volcengine/OpenViking/commit/8c1c3f3608364ee0bb0e45f73478771a68aebdf5[WEB]
- https://github.com/volcengine/OpenViking[PACKAGE]
- https://github.com/volcengine/OpenViking/releases/tag/v0.3.3[WEB]
- https://www.vulncheck.com/advisories/openviking-missing-authorization-via-task-polling[WEB]
- https://pypi.org/project/openviking[PACKAGE]
- https://github.com/advisories/GHSA-h336-2wxm-pr6q[ADVISORY]