CVE-2026-14687CWE-187CWE-697

666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison

Medium · published July 5, 2026

CVSS v4.0
6.9
EPSS
1%
Percentile
42.7
In the wild
Unconfirmed
What it is

A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine search-result Deduplication. Executing a manipulation can lead to partial string comparison. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.

The record
Technical detail
CVSS v4.0
6.9 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
0.00528 · 42.7th percentile
Weaknesses
CWE-187 · Partial String Comparison; CWE-697 · Incorrect Comparison
Published
2026-07-05T00:30Z
EPSS history
Timeline
  • 05 JUL 00:30Z
    666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
    cvelistv5