Known Vulnerabilities for Assistant by Synology
Listed below are 3 of the newest known vulnerabilities associated with "Assistant" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73847 json | Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_t... | Not Provided | 2026-08-14 | 2026-08-14 |
| CVE-2026-72581 json | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to m... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-71247 json | Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fet... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-67622 json | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that al... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-66601 json | Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-66600 json | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-66591 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIb... | Not Provided | 2026-08-18 | 2026-08-21 |
| CVE-2026-66061 json | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Comp... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-66060 json | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Compani... | Not Provided | 2026-08-07 | 2026-08-13 |
| CVE-2026-65975 json | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to ... | Not Provided | 2026-07-29 | 2026-07-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Assistant | 6.2-23733 | |||
| Application | Synology | Assistant | 6.1-15163 | |||
| Application | Synology | Assistant | 6.1-15030 | |||
| Application | Synology | Assistant | 6.0-7319 | |||
| Application | Synology | Assistant | 5.2-5566 | |||
| Application | Synology | Assistant | 5.1-5005 | |||
| Application | Synology | Assistant | 5.1-5002 | |||
| Application | Synology | Assistant | 5.0-4448 | |||
| Application | Synology | Assistant | 5.0-4418 | |||
| Application | Synology | Assistant | 4.3-4359 | |||
| Application | Synology | Assistant | 4.3-4206 | |||
| Application | Synology | Assistant | 4.2-3508 | |||
| Application | Synology | Assistant | 4.2-3179 | |||
| Application | Synology | Assistant | 4.1-2647 | |||
| Application | Synology | Assistant | 4.1-2638 | |||
| Application | Synology | Assistant | 4.1-2636 | |||
| Application | Synology | Assistant | 4.0-2216 | |||
| Application | Synology | Assistant | 4.0-2196 | |||
| Application | Synology | Assistant | 3.2-1920 | |||
| Application | Synology | Assistant | 3.1-1593 |