Gryph AI coding agent security layer logs sensitive file content (CVE-2026-45046)
Gryph, a security layer for AI coding agents, stored sensitive file-write content (ContentPreview, OldString, NewString) in a local SQLite database at its default 'standard' log level, bypassing its own sensitive file filter and documented log level behaviour. The issue affects versions prior to 0.7.0 and is fixed in 0.7.0.
Disclosed 27 May 2026 · Record updated 13 September 2026
Impact
Potentially sensitive file content was written to a local SQLite log database despite Gryph's sensitive file filter and log level contracts, risking exposure of confidential code or data.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45046
