Quivr · Issues· 34 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #3667
EU AI Act Compliance Scan Results — Sharing Findings for Feedback
Updated Sep 13, 2026 - #3717
[security] Hardcoded Flask secret key enables session cookie forgery
Updated Sep 9, 2026 - #3716
[security] Arbitrary code execution via unsafe FAISS/pickle deserialization when loading a brain
Updated Sep 6, 2026 - #2004
[Bug]:
bugarea: frontendtype: dependenciesUpdated Aug 17, 2026 - #3701
Fix Langfuse dependency incompatibility and upgrade to Python SDK v4
bugarea: backendUpdated Jul 21, 2026 - #3700
Volunteer for maintainer review
Updated Jul 13, 2026 - #3698
Prompt IDOR - any authenticated user can read and overwrite any prompt (system-prompt hijacking)
bugarea: backendUpdated Jul 3, 2026 - #3697
Chat IDOR - unauthenticated-of-ownership read, delete, and message injection on any chat
bugarea: backendUpdated Jul 3, 2026 - #3691
[Security] RCE via Pickle Deserialization in Brain.load()
bugUpdated Jun 26, 2026