CVE-2026-67348: Julep-Ai Julep
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.
Affected products
- Julep-Ai Julep
Published 2026-07-30. Last modified 2026-07-30.