CVE Explorer
CVE-2026-33879
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks. FLIP users are external to the organization, increasing credential reuse risk. As of time of publication, it is unclear if a patch is available.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"FLIP","vendor":"londonaicentre","versions":[{"status":"affected","version":"<= 0.1.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:48a459f177db3e3218b37a477990c66d9bc0a53f0e085f3e0dbd96f394b756df · sha256:a730b868c37d443c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":2.7,"baseSeverity":"LOW","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:48a459f177db3e3218b37a477990c66d9bc0a53f0e085f3e0dbd96f394b756df · sha256:a730b868c37d443c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-307","description":"CWE-307: Improper Restriction of Excessive Authentication Attempts","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:48a459f177db3e3218b37a477990c66d9bc0a53f0e085f3e0dbd96f394b756df · sha256:a730b868c37d443c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/londonaicentre/FLIP/security/advisories/GHSA-p34f-488j-5cwv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/londonaicentre/FLIP/security/advisories/GHSA-p34f-488j-5cwv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:48a459f177db3e3218b37a477990c66d9bc0a53f0e085f3e0dbd96f394b756df · sha256:a730b868c37d443c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.