← Back to CVE search

CVE-2026-37012

PentestGPT

Description

A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials.

EPSS 0.22100000000000003%Risk 0
View source
Published
2026-08-27 20:17:41
Affected versions
==1.0.0
Type
Library
Last modified
2026-08-27 20:17:41
Vector
Pending