CVE-2026-13507 | volcengine OpenViking up to 0.3.21 Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 ID data authenticity (Issue 2263)

SecurityVulns

A vulnerability classified as problematic was found in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The manipulation of the argument ID results in insufficient verification of data authenticity.

This vulnerability is cataloged as CVE-2026-13507. The attack may be launched remotely. There is no exploit available.

The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More