Known Vulnerabilities for Assistant by Synology

Listed below are 1 of the newest known vulnerabilities associated with "Assistant" by "Synology".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-34205 Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (former... Not Provided 2026-03-27 2026-04-01
CVE-2026-33873 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant ... Not Provided 2026-03-27 2026-04-01
CVE-2026-33654 nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email ch... Not Provided 2026-03-27 2026-03-30
CVE-2026-33045 Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02... Not Provided 2026-03-27 2026-04-01
CVE-2026-33044 Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02... Not Provided 2026-03-27 2026-04-01
CVE-2025-63065 Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assista... Not Provided 2025-12-09 2026-04-01
CVE-2025-62154 Missing Authorization vulnerability in recorp AI Content Writing Assistant (Content Writer, ChatGPT, Image Generator) All in ... Not Provided 2025-12-31 2026-04-01
CVE-2025-60155 Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured ... Not Provided 2025-09-26 2026-04-01
CVE-2025-59590 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIb... Not Provided 2025-09-22 2026-04-01
CVE-2025-58829 Server-Side Request Forgery (SSRF) vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) A... Not Provided 2025-09-05 2026-04-01

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationSynologyAssistant6.2-23733AllAllAll
ApplicationSynologyAssistant6.1-15163AllAllAll
ApplicationSynologyAssistant6.1-15030AllAllAll
ApplicationSynologyAssistant6.0-7319AllAllAll
ApplicationSynologyAssistant5.2-5566AllAllAll
ApplicationSynologyAssistant5.1-5005AllAllAll
ApplicationSynologyAssistant5.1-5002AllAllAll
ApplicationSynologyAssistant5.0-4448AllAllAll
ApplicationSynologyAssistant5.0-4418AllAllAll
ApplicationSynologyAssistant4.3-4359AllAllAll
ApplicationSynologyAssistant4.3-4206AllAllAll
ApplicationSynologyAssistant4.2-3508AllAllAll
ApplicationSynologyAssistant4.2-3179AllAllAll
ApplicationSynologyAssistant4.1-2647AllAllAll
ApplicationSynologyAssistant4.1-2638AllAllAll
ApplicationSynologyAssistant4.1-2636AllAllAll
ApplicationSynologyAssistant4.0-2216AllAllAll
ApplicationSynologyAssistant4.0-2196AllAllAll
ApplicationSynologyAssistant3.2-1920AllAllAll
ApplicationSynologyAssistant3.1-1593AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report