← Back to CVE List
CVE-2026-105161NVD
Vulnerability Summary
A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- invariant-systems-ai aiir >= 1.0
- invariant-systems-ai aiir >= 1.1
- invariant-systems-ai aiir >= 1.2
- invariant-systems-ai aiir >= 1.3
- invariant-systems-ai aiir >= 1.4
- invariant-systems-ai aiir >= 1.5
- invariant-systems-ai aiir >= 1.6
- invariant-systems-ai aiir >= 1.7.0
Not provided by cveorg for this CVE.