CVE-2026-14630Disclosure

LOWCVSS 1.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the component Memory Recall Handler. The manipulation leads to use of weak hash. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is f57277fdd9ba373ace72d83c272023ec67f720d6. It is suggested to install a patch to address this issue. The project confirms (translated from Chinese): "We now require session ownership verification in methods such as `username`, `sessionowner`, etc., and we've chat()changed the generation of `sessionowner` to include verified user identity and security context metadata."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327CWE-328

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-04: 2Technical Details · 2026-07-04: 207-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14630 A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agen… https://www.cve.org/CVERecord?id=CVE-2026-14630 ----- Traducción: Se ha encontrado u… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑14630, noting it impacts ForceInjection AI‑fundermentals 2.0/3.0, specifically the get_conversation_history function, and includes a link to the official CVE record.

    0000029
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14630 A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agen… https://www.cve.org/CVERecord?id=CVE-2026-14630

    Post summary

    A new vulnerability (CVE-2026-14630) affecting ForceInjection AI-fundermentals 2.0/3.0’s get_conversation_history function has been identified; no exploit tools, active exploitation, patches, or false‑positive claims are mentioned.

    00000833
    57.7K followersView on X

Explore more