Youdao Qanything Local File Inclusion Vulnerability Allowing Arbitrary File Read and Potential Remote Code Execution
Vulnerability
A local file inclusion vulnerability has been identified in Youdao Qanything version 2.0.0. This vulnerability allows attackers to read arbitrary files from the file system, which could lead to remote code execution by accessing private SSH keys, confidential files, source code, and configuration files.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive files, including private SSH keys, which could be used for remote code execution.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
3.3remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
