Executive brief
BettaFish is an AI-powered public opinion analysis tool used to monitor and summarize social media and news trends. A flaw in its data processing engine causes it to incorrectly discard unique search results if they lack a web link and share the same first 100 characters of text. This can lead to incomplete or misleading reports, potentially causing organizations to miss critical information or contradictory viewpoints during a crisis.
Technical details
A vulnerability exists in the `_deduplicate_results` function within `InsightEngine/agent.py` of BettaFish up to version 1.2.1. The root cause is an incorrect comparison logic (CWE-187/CWE-697) where results without a URL are deduplicated based solely on a truncated 100-character prefix of their content. A remote attacker or specific data conditions can trigger this behavior, causing the system to silently drop distinct records that share a common prefix but contain different information after the 100th character. This impacts the integrity of downstream processes including sentiment analysis and final report generation. A fix has been proposed in pull request #689 but is currently awaiting official merge.
Affected products
- 666ghj BettaFish up to 1.2.1
Timeline
- 2026-06-03: disclosed: Issue and fix pull request opened on GitHub
- 2026-07-05: advisory: CVE published via VulDB/NVD