Youdao Qanything Local File Inclusion Vulnerability Allowing Arbitrary File Read and Potential Remote Code Execution

Vulnerability

A local file inclusion vulnerability has been identified in Youdao Qanything version 2.0.0. This vulnerability allows attackers to read arbitrary files from the file system, which could lead to remote code execution by accessing private SSH keys, confidential files, source code, and configuration files.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive files, including private SSH keys, which could be used for remote code execution.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.