A high-severity vulnerability tracked as CVE-2026-70619 affected Odysseus before commit bf325f6b2185cb42bc5d8f5713a64aecffb766d4, allowing any authenticated non-admin user to access embedding management routes that lacked an admin authorization check. Reports identified exposed routes under /api/embeddings/*, including endpoint configuration and related model management functions, enabling a regular user to overwrite the server-wide embedding backend with an attacker-controlled URL or delete the configuration entirely. The issue was classified as CWE-862 with a CVSS 3.1 rating of High.
By changing the global embedding endpoint, an attacker could cause subsequent embedding-related content—including chat messages, RAG queries, memory entries, and vault text—to be sent in plaintext to infrastructure they controlled, while deletion of the endpoint could disrupt embedding services for all users. Security reports and the project’s GitHub issues also warned that the endpoint health-check behavior created SSRF risk, aligning with CWE-918, because the server could be induced to make outbound requests to attacker-supplied hosts. Maintainers said they fixed the authorization flaw by adding require_admin to the embeddings router and later added URL validation and other SSRF hardening for custom embedding endpoints.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry for CVE-2026-70619 was received by disclosure@vulncheck.com. The record describes a missing authorization flaw in Odysseus before commit bf325f6 that lets authenticated non-admin users manage embedding endpoint routes, enabling data exposure and denial of service.
A public write-up documenting broken access control and SSRF in the Odysseus embedding endpoint was published at aydinnyunus.github.io. The CVE record later referenced this write-up as part of the vulnerability documentation.
On issue #132, collaborator NicholaiVogel stated that the non-admin access problem appeared fixed on the main branch by commit bf325f6 and said issue #80 had been closed for the authentication fix. He also noted that URL validation for the server-side probe remained unresolved.
Aydinnyunus opened GitHub issue #132 describing improper authentication in Odysseus embeddings management routes that let a non-admin user change the global embedding endpoint, persist malicious configuration, exfiltrate plaintext embedding-related data, and trigger SSRF and denial-of-service conditions. The report included proof-of-concept details and recommended adding admin checks and URL validation.
Darkroom4364 opened GitHub issue #80 reporting that Odysseus /api/embeddings/* routes were accessible to authenticated non-admin users, allowing changes to shared embedding configuration and assets. The report recommended requiring admin privileges and adding regression tests.
A collaborator stated that Odysseus had fixed both the improper-authentication and SSRF components on main. Maintainers said POST /api/embeddings/endpoint now validates URLs before outbound health checks and rejects non-HTTP(S) schemes and several unsafe address classes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceaydinnyunus.github.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.