Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Julep-ai
Julep-ai julep |
|
| Vendors & Products |
Julep-ai
Julep-ai julep |
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants. | |
| Title | Julep Insecure Direct Object Reference via GET /executions/{execution_id} | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-30T15:17:09.983Z
Reserved: 2026-07-29T13:36:36.277Z
Link: CVE-2026-67348
Updated: 2026-07-30T15:17:05.493Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:26:30Z
-
CWE-639
Authorization Bypass Through User-Controlled Key