Junglewise Threat Intelligence

CVE-2026-13507: volcengine OpenViking insufficient verification of data authenticity in VectorDB

CVE-2026-13507 · Severity: medium · CVSS 5 · Published 2026-06-28

Technologies: Volcengine Openviking.

Executive brief

OpenViking is an open-source database used to manage context and memory for AI Agents. A security flaw in how the system identifies data records and generates encryption keys could allow different users or accounts to accidentally share the same data labels or cryptographic keys. In practice, this could lead to data being associated with the wrong account or unauthorized access to sensitive information if an attacker can predict or manipulate record IDs.

Technical details

A vulnerability exists in OpenViking's Local VectorDB Primary-key Label Handler and cryptographic provider. The function 'str_to_uint64' in 'openviking/storage/vectordb/utils/str_to_uint64.py' generates internal labels by hashing only the record ID, omitting critical security context such as account_id, context_type, or owner_space. Additionally, the HKDF key derivation in 'openviking/crypto/providers.py' fails to include a unique purpose or version parameter. A remote attacker with low privileges could exploit these collisions to cause data rebinding or access keys intended for different logical purposes. A fix has been proposed in pull request #2268 to bind storage and crypto keys to the full security context.

Affected products

  • volcengine OpenViking up to 0.3.21

Timeline

  • 2026-05-27: disclosed: Issue reported on GitHub and pull request submitted
  • 2026-06-28: advisory: CVE published via VulDB/NVD

References