CVE-2026-14630 | ForceInjection AI-fundermentals 2.0/3.0 Memory Recall smart_customer_service.py get_conversation_history weak hash (Issue 17)

SecurityVulns

A vulnerability was found in ForceInjection AI-fundermentals 2.0/3.0. It has been rated as problematic. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the component Memory Recall Handler. The manipulation leads to use of weak hash.

This vulnerability is referenced as CVE-2026-14630. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

It is suggested to install a patch to address this issue.

The project confirms (translated from Chinese): “We now require session ownership verification in methods such as `username`, `sessionowner`, etc., and we’ve chat()changed the generation of `sessionowner` to include verified user identity and security context metadata.”VulDB Recent EntriesRead More