{"data":{"id":"b7934e59-693c-4ead-888a-d47b276ae1f5","title":"GHSA-w7qg-j435-78qw: Use of hard-coded, security-relevant constants in deepset-ai/haystack","summary":"Haystack, the deepset-ai GitHub repository, uses hard-coded, security-relevant constants in version 1.15.0 and earlier. The advisory GHSA-w7qg-j435-78qw covers this use of fixed values where a secret or setting should not be fixed.","solution":"A patch is available at commit 5fc84904f198de661d5b933fde756aa922bf09f1.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-w7qg-j435-78qw","publishedAt":"2023-03-30T12:30:15.000Z","cveId":"CVE-2023-1712","cweIds":["CWE-547"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":[],"issueType":"vulnerability","affectedPackages":["farm-haystack@<= 1.15.0"],"affectedPackageNames":["farm-haystack"],"affectedPackageRefs":["pypi:farm-haystack"],"affectedVendors":[],"affectedVendorsRaw":["Haystack"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.0085,"epssCheckedAt":"2026-10-10T04:57:05.197Z","kevDateAdded":null,"advisoryAliases":["GHSA-w7qg-j435-78qw"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2023-03-30T12:30:15.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}