Liquid-co OpenSave

2 known vulnerabilities in Liquid-co OpenSave, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-103398 CVSS 8.6 high OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can…
  • CVE-2026-103397 CVSS 6.3 medium OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired…