CVE-2026-13482Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The manipulation results in use of weak hash. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327CWE-328

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-28: 3Technical Details · 2026-06-28: 206-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-13482 A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID … https://www.cve.org/CVERecord?id=CVE-2026-13482

    Post summary

    A new vulnerability, CVE‑2026‑13482, was detected in SkyPilot up to version 0.12.0, affecting the username.encode function in sky/users/server.py; no exploit details or patch information were provided.

    00010943
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13482 A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID … https://www.cve.org/CVERecord?id=CVE-2026-13482 ----- Traducción: CVE-2026-13482 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability (CVE-2026-13482) affecting skypilot up to 0.12.0 is disclosed, specifying a flaw in the username.encode function within sky/users/server.py.

    0000041
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13482 Weak Hash Vulnerability in SkyPilot User ID Handler Up to 0.12.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13482

    Post summary

    The text announces CVE-2026-13482 as a weak hash vulnerability in SkyPilot User ID Handler up to 0.12.0, but provides no exploit, patch, or detailed technical information.

    00000104
    4.1K followersView on X

Explore more