Security Advisories
This page lists the security advisories Curiosity has published for Curiosity Workspace. An advisory is published for every security issue that reached a released build and requires customer action — an upgrade, a configuration change, or a review of existing data.
Each advisory states the affected builds, the build that contains the fix, a CVSS v4.0 base score and vector, and what an administrator has to do.
Published advisories
| Advisory | Title | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-88817 | Privilege escalation via access group creation | 8.7 High | Builds before 70363 |
70363 |
2026-09-10 |
How advisories are published
- An advisory goes out once a build containing the fix is available as
curiosityai/curiosity:<build>on Docker Hub, so there is always an upgrade path at the time of publication. - Severity is scored with CVSS v4.0. Both the base score and the full vector string are published so you can re-score the issue for your own environment.
- Weaknesses are classified with CWE identifiers.
- Reporters are credited by name with their consent.
- Advisories are not amended silently. Material corrections are added as a dated entry at the bottom of the advisory.
Issues found and fixed internally before they shipped in a released build are not published here.
Report a vulnerability
Send reports to security@curiosity.ai. See Report a Security Issue for what to include, our response times, and the testing rules.