The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.
History

Mon, 19 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Thelibrarian
Thelibrarian thelibrarian
Vendors & Products Thelibrarian
Thelibrarian thelibrarian

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 13:00:00 +0000

Type Values Removed Values Added
Description The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used with SSRF-style behavior to perform GET requests to internal IP addresses and services, enabling scanning of the Hertzner cloud environment that TheLibrarian uses. The vendor has fixed the vulnerability in all affected versions.
Title CVE-2026-0613
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2026-01-16T12:46:02.733Z

Updated: 2026-01-16T21:41:53.497Z

Reserved: 2026-01-05T17:40:07.817Z

Link: CVE-2026-0613

cve-icon Vulnrichment

Updated: 2026-01-16T21:41:46.800Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T13:16:11.780

Modified: 2026-01-16T22:16:19.360

Link: CVE-2026-0613

cve-icon Redhat

No data.