CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Mintplex Anything-LLM Path Traversal Vulnerability Leading to Arbitrary File Read/Write and Privilege Escalation
A path traversal vulnerability has been identified in the normalizePath function of Mintplex Labs' Anything-LLM, specifically in version git 296f041. This vulnerability allows for arbitrary file read and write operations within the application's storage directory. The issue arises because the normalizePath function fails to properly sanitize certain file path inputs, enabling malicious users to traverse directories and manipulate files. Exploiting this vulnerability can lead to unauthorized privilege escalation, particularly from a manager to an admin role.
aimhubio Aim Unrestricted Code Execution Vulnerability via Outdated safer_getattr() Function
A vulnerability allowing unrestricted code execution has been identified in aimhubio Aim version 3.22.0. The issue arises in the AimQL query language, which relies on an outdated version of the safer_getattr() function from RestrictedPython. This outdated version fails to properly restrict access to the str.format_map() method, enabling attackers to leak server-side secrets or potentially execute arbitrary code. The vulnerability exists because str.format_map() can read arbitrary attributes from Python objects, allowing access to sensitive variables such as environment variables. If an attacker can write files to a known location on the Aim server, they could use str.format_map() to load a malicious dynamic library into the Python interpreter, leading to unrestricted code execution.
Mintplex Anything-LLM Network Discovery Vulnerability Allowing Backend Access
A vulnerability in Mintplex Labs Anything-LLM version 1.5.11 for Windows desktop has been identified, where the application opens server port 3001 on all interfaces (0.0.0.0) without authentication. This exposure allows attackers to gain full access to the backend, potentially leading to actions such as deleting all workspace data.
Prefect CORS Misconfiguration Vulnerability Allowing Unauthorized Data Access
A Cross-Origin Resource Sharing (CORS) misconfiguration has been identified in Prefect version 2.20.2. This vulnerability allows unauthorized domains to access sensitive data, potentially leading to unauthorized database access, data leaks, service disruptions, and risks to data integrity.
Significant Gravitas AutoGPT Command Injection Vulnerability in Workflow Checker
A command injection vulnerability has been identified in the workflow-checker.yml file of Significant Gravitas AutoGPT, affecting all versions up to the latest release. The vulnerability arises from the insecure handling of untrusted user input, specifically the 'github.head.ref' variable, which can be exploited by injecting arbitrary commands. An attacker could create a branch name containing a malicious payload and submit a pull request, potentially gaining reverse shell access or stealing sensitive tokens and keys.
aimhubio Aim Text Explorer Component Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in the Text Explorer component of aimhubio/aim, specifically in version 3.23.0. This vulnerability allows for the execution of arbitrary JavaScript by exploiting the application's tracked text feature. The issue arises because HTML content is rendered using dangerouslySetInnerHTML without proper sanitization, leaving the application open to script injection. Malicious HTML can be injected during the training process, and when the tracked text is viewed in the Text Explorer, the injected JavaScript is executed.
Vanna-AI Vanna Server-Side Request Forgery Vulnerability When Using DuckDB
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the latest version of Vanna-AI Vanna, specifically when DuckDB is used as the database. This vulnerability allows attackers to exploit default DuckDB functions, such as 'read_csv', 'read_csv_auto', 'read_text', and 'read_blob', to make unauthorized requests to internal or external resources. As a result, sensitive data, internal systems, and potentially further attack vectors could be compromised.
danswer-ai Danswer Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in version 1.4.1 of danswer-ai/danswer. This vulnerability allows attackers to perform unauthorized actions in the context of the victim's browser, such as connecting to a malicious Slack Bot, inviting users, and deleting chats. The application lacks any CSRF protection, leaving it vulnerable to these types of attacks.
Ollama/Ollama Divide-By-Zero Vulnerability Leading to Denial-of-Service
A divide-by-zero vulnerability has been identified in Ollama/Ollama version 0.3.3. This issue arises when importing GGUF models that contain a manipulated type for 'block_count' in the Modelfile. The vulnerability can cause a denial-of-service condition by crashing the server while processing the model.
h2oai h2o-3 Denial-of-Service Vulnerability in Typeahead Endpoint
A denial-of-service vulnerability has been identified in h2oai h2o-3 version 3.46.0. The issue arises in the typeahead endpoint, which performs a HEAD request to verify the existence of a specified resource without a timeout. This lack of timeout allows an attacker to send multiple requests to a server they control, causing the application to hang and become unresponsive to other requests.
aimhubio aim Denial-of-Service Vulnerability Due to Missing Timeouts in External Data Requests
A denial-of-service vulnerability has been identified in aimhubio aim version 3.23.0. Certain methods in the client used by the aim tracking server to request data from external servers do not have timeouts set. This oversight causes the server to wait indefinitely for a response, leading to a denial-of-service condition where the tracking server cannot respond to other requests while waiting. The issue arises in the '_run_read_instructions' method and similar calls that lack timeouts, causing the tracking server to become unresponsive.
OpenWebUI Arbitrary File Upload Vulnerability in Audio API Endpoint Allowing Path Traversal and Potential Remote Code Execution
A vulnerability has been identified in OpenWebUI version 0.3.0 within the audio API endpoint '/audio/api/v1/transcriptions'. This vulnerability allows for arbitrary file uploads due to inadequate validation of the 'file.content_type' and the acceptance of user-controlled filenames, which creates a path traversal issue. An authenticated user could exploit this to overwrite critical files in the Docker container, possibly leading to remote code execution as the root user.
danswer Unauthenticated User Privilege Escalation Vulnerability Leading to Denial-of-Service
A vulnerability in danswer-ai/danswer version 0.4.1 allows unauthenticated users to create credentials and link them to existing connectors. This issue arises because basic users can perform actions intended for admin users, potentially leading to excessive resource consumption and causing a Denial-of-Service (DoS) condition, along with other significant stability and security issues.
Vanna SQL Injection Vulnerability Allowing Arbitrary File Read on Snowflake Database
A SQL injection vulnerability has been identified in Vanna version 0.6.3, specifically within its file staging operations involving the Snowflake database. This issue arises when using the 'PUT' and 'COPY' commands, allowing unauthenticated remote users to exploit exposed SQL queries through a Python Flask API. The exploitation enables the reading of arbitrary local files on the victim server, such as '/etc/passwd'.
Open Web UI PDF Generation Service Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in open-webui/open-webui version 0.3.10. The issue arises in the 'api/v1/utils/pdf' endpoint, which lacks authentication, allowing unauthenticated attackers to access the PDF generation service. Exploitation involves sending a POST request with a large payload, potentially exhausting server resources and causing a denial-of-service condition. Additionally, unauthorized users can generate PDFs through this endpoint without any verification, leading to service misuse and possible operational and financial repercussions.
imartinez PrivateGPT Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in imartinez/privategpt version 0.5.0. This issue arises in the file upload process, where attackers can upload malicious SVG files. When a victim clicks on the link to the uploaded file, the SVG executes JavaScript in the victim's browser. This vulnerability could lead to theft of user data, session hijacking, distribution of malware, or phishing attacks.
Danswer Denial-of-Service Vulnerability via Malformed Multipart Boundary
A denial-of-service vulnerability has been identified in danswer-ai/danswer version 0.3.94. The issue arises when an attacker uploads a file with a malformed multipart boundary, specifically by adding an excessive number of characters to the end of the boundary. This causes the server to continuously process each character, leading to application unavailability. The vulnerability can be exploited by sending a single crafted request, impacting all users on the server.
Netease Youdao QAnything Stored Cross-Site Scripting Vulnerability
A stored cross-site scripting vulnerability has been identified in Netease Youdao QAnything, affecting all versions prior to the fix. This vulnerability allows attackers to upload malicious knowledge files to the knowledge base, which can then trigger XSS attacks during user chats.
netease-youdao qanything Cross-Site Request Forgery Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The vulnerability arises from overly permissive CORS headers that allow all cross-origin requests. This issue impacts all backend endpoints, enabling unauthorized actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
Youdao Qanything CORS Misconfiguration Vulnerability Allowing Same-Origin Policy Bypass
A CORS misconfiguration vulnerability has been identified in Youdao Qanything version 1.4.1. This issue allows attackers to bypass the Same-Origin Policy, potentially leading to the exposure of sensitive information. A properly implemented restrictive CORS policy is essential to prevent such security vulnerabilities.
Gradio Open Redirect Vulnerability
A medium-severity open redirect vulnerability has been identified in the latest version of Gradio. This issue allows attackers to redirect users to malicious websites by exploiting URL encoding. The vulnerability can be triggered by sending a crafted request to the application, which then responds with a 302 redirect to an attacker-controlled site.
Lightning AI PyTorch Lightning Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Lightning AI PyTorch Lightning version 2.3.2. The issue arises when an attacker sends an unexpected POST request to the '/api/v1/state' endpoint of 'LightningApp'. This vulnerability is caused by improper management of unexpected state values, leading to a server shutdown.
Lightning-AI PyTorch Lightning Arbitrary File Write Vulnerability in LightningApp on Windows
A vulnerability in Lightning-AI PyTorch Lightning version 2.3.2 allows arbitrary file write or overwrite actions when the LightningApp is run on a Windows host. This issue is present in the '/api/v1/upload_file/' endpoint, where an attacker can manipulate the filename to write to or replace files in sensitive locations, potentially leading to remote code execution. The vulnerability arises from improper handling of file upload requests, allowing for directory traversal and exploitation of the Windows file system.
privategpt Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in privategpt version 0.5.0. The issue arises when a file is uploaded and a large number of characters are appended to the end of the multipart boundary. This causes the system to continuously process the excess characters, leading to prolonged unavailability of the service. The excessive resource consumption can disrupt operations, cause data inaccessibility, and result in a loss of productivity. In testing, adding nearly 10 million characters rendered privategpt inaccessible for several hours.
Open-WebUI Cross-Site Scripting Vulnerability Allowing Privilege Escalation and Data Theft
A cross-site scripting (XSS) vulnerability has been identified in Open-WebUI versions through 0.3.8. The issue arises in the tooltip HTML construction function, allowing attackers to execute actions with the victim's privileges. This could include stealing chat history, deleting chats, and escalating their account to admin status if the victim is an admin.
Open WebUI Stored Cross-Site Scripting Vulnerability Allowing Arbitrary Code Execution
A stored cross-site scripting vulnerability has been identified in Open WebUI version 0.3.8. The issue arises in the '/api/v1/models/add' endpoint, where the model description field is not properly sanitized before being displayed in chat. This flaw enables an attacker to inject malicious scripts that can be executed by any user, including administrators. The exploitation of this vulnerability could lead to arbitrary code execution on the server.
open-webui Markdown Conversion Endpoint Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in open-webui version 0.3.8. The issue arises from an endpoint that converts markdown to HTML, which is exposed without authentication. A maliciously crafted markdown payload can be sent to this endpoint, causing the server to spend an excessive amount of time processing the conversion. As a result, the server becomes unresponsive to other requests until the conversion is complete, leading to a significant degradation of service.
open-webui/open-webui Server-Side Request Forgery Vulnerability in Models Endpoint
A Server-Side Request Forgery (SSRF) vulnerability has been identified in open-webui/open-webui version 0.3.8. The issue arises in the '/openai/models' endpoint, where users can manipulate the OpenAI URL without any validation. This flaw enables attackers to direct requests to arbitrary URLs, potentially accessing internal services and extracting sensitive information, such as instance secrets from cloud providers like AWS.
danswer-ai Danswer ZulipConnector Arbitrary File Overwrite Vulnerability
An arbitrary file overwrite vulnerability has been identified in the ZulipConnector of the danswer-ai/danswer application, specifically in the latest version. This vulnerability arises in the load_credentials method, where user-controlled input for realm_name and zuliprc_content is used to create file paths and write file contents. As a result, attackers can overwrite or create arbitrary files if a zuliprc- directory already exists in the temporary directory.
danswer-ai Danswer CORS Misconfiguration Vulnerability Allowing Data Theft
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability has been identified in danswer-ai/danswer version 1.4.1. This vulnerability allows attackers to steal sensitive information, including chat contents, API keys, and other data. The issue arises from improper validation of the origin header, which enables malicious web pages to make unauthorized requests to the application's API.
Open-WebUI Remote Code Execution Vulnerability via Cross-Site Request Forgery
A remote code execution vulnerability has been identified in Open-WebUI versions through 0.3.8. This issue allows non-admin users to execute arbitrary code by exploiting Cross-Site Request Forgery (CSRF) vulnerabilities. The application uses cookies for authentication with the SameSite attribute set to lax, and it lacks CSRF tokens. This combination enables an attacker to create a malicious HTML document that, when opened by a victim, can alter the Python code of an existing pipeline and execute arbitrary code with the victim's privileges.
danswer-ai/danswer Regular Expression Denial-of-Service Vulnerability
A Regular Expression Denial-of-Service (ReDoS) vulnerability has been identified in danswer-ai/danswer version 1. This vulnerability allows an attacker to manipulate regular expressions, significantly degrading the application's response time and potentially causing it to become completely unusable.
ONNX Framework Arbitrary File Overwrite Vulnerability in Download Model Function
A vulnerability exists in the ONNX framework, specifically in the download_model function, in versions prior to and including 1.16.1. This vulnerability allows for arbitrary file overwriting due to insufficient protection against path traversal attacks in malicious tar files. An attacker could exploit this to overwrite files in the user's directory, potentially leading to remote command execution.
Mintplex Anything-LLM Dockerized Version Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Dockerized version of Mintplex Labs Anything-LLM, specifically in the latest release with digest 1d9452da2b92. The issue arises when an audio file with an extremely low sample rate is uploaded, causing the transcription functionality to crash the entire site instance. This problem is linked to the localWhisper implementation, where resampling the audio from 1 Hz to 16 kHz rapidly consumes available memory, resulting in the Docker instance being terminated by the instance manager.
h2oai h2o-3 Denial-of-Service Vulnerability in ImportFiles Endpoint
A denial-of-service vulnerability has been identified in h2oai h2o-3 version 3.46.1. The issue arises in the '/3/ImportFiles' endpoint, which accepts a GET parameter named 'path'. An attacker can exploit this vulnerability by setting the 'path' parameter to reference itself recursively. This causes the server to repeatedly invoke the endpoint, eventually saturating the request queue and preventing the server from processing other incoming requests.
Danswer Improper Access Control Vulnerability Allowing Unauthorized Chat Management
An improper access control vulnerability has been identified in Danswer version 0.3.94. This issue allows the first user created in the system to view, modify, and delete chats created by an Admin. Such access can result in unauthorized exposure of sensitive information, disruption of data integrity, and potential violations of compliance regulations.
H2O.ai H2O-3 Denial-of-Service Vulnerability via Large GZIP File Uploads
A denial-of-service vulnerability has been identified in H2O.ai H2O-3 version 3.46.0.2. The issue arises when a large GZIP file is uploaded and repeatedly parsed, causing the server to become unresponsive. This unresponsiveness is due to memory exhaustion and a high number of concurrent, slow-running jobs. The vulnerability stems from improper handling of highly compressed data, which leads to significant data amplification.
Vanna.ai SQL Injection Vulnerability in generate_sql Function
A SQL injection vulnerability has been identified in Vanna.ai version 0.6.2. The issue arises from inadequate validation of user input, allowing attackers to inject additional SQL commands that could be executed against the database. This vulnerability occurs when the 'generate_sql' function processes responses from the language model (LLM) and extracts SQL queries. By inserting a semi-colon between a data field and an injected command, an attacker can manipulate the extracted SQL and execute their own queries, potentially accessing or modifying data beyond the intended scope.
aimhubio Aim Cross-Site Request Forgery Vulnerability in Tracking Server
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in aimhubio/aim version 3.22.0, specifically within the tracking server. This vulnerability arises from overly permissive Cross-Origin Resource Sharing (CORS) settings, which allow cross-origin requests from any origin. As a result, all endpoints on the tracking server are susceptible to CSRF attacks. This vulnerability can be exploited in conjunction with other existing vulnerabilities, such as remote code execution, denial of service, and arbitrary file read/write.
Lunary Broken Access Control Vulnerability Allowing Unauthorized Template Modification
A broken access control vulnerability exists in Lunary AI's Lunary application, specifically in versions 1.2.7 prior to 1.4.2. This vulnerability allows authenticated attackers to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. The issue arises from insufficient access controls, enabling attackers to manipulate template data across user accounts.
Parisneo Lollms Path Traversal Vulnerability in Web UI
A relative path traversal vulnerability has been identified in the sanitize_path function of Parisneo Lollms Web UI version 10 through latest. This vulnerability allows attackers to bypass path sanitization by using relative paths, such as './', potentially leading to unauthorized access to directories within the personality_folder on the victim's computer.
open-webui Session Fixation Vulnerability Allowing Administrator Account Takeover
A session fixation vulnerability has been identified in open-webui version 0.3.8. This issue allows an attacker with a user-level account to exploit the session management of the application. The vulnerability arises because the session cookie for all users is configured with the default 'SameSite=Lax' and lacks the 'Secure' flag, enabling the cookie to be transmitted over HTTP to a cross-origin domain. An attacker can embed a malicious markdown image in a chat, which, when viewed by an administrator, sends the admin's session cookie to the attacker's server. This exploitation can lead to a stealthy takeover of the administrator's account, with the potential for remote code execution due to the elevated privileges of admin accounts.
Open-WebUI Access Control Vulnerability Allowing Unauthorized Admin Detail Access
A vulnerability in Open-WebUI version 0.3.8 allows attackers to access admin details due to improper access control. The application fails to verify if the requester is an administrator, enabling direct calls to the '/api/v1/auths/admin/details' endpoint to retrieve information about the first admin (owner).
Open WebUI Improper Access Control Vulnerability Allowing Unauthorized Prompt Access
A vulnerability in Open WebUI version 0.3.8 allows attackers to bypass access controls and view prompts created by administrators. The application fails to verify user roles, enabling attackers to access the /api/v1/prompts/ endpoint and retrieve all prompt information, including ID values. This information can then be exploited using the /api/v1/prompts/command/{command_id} endpoint to obtain specific prompt details.
open-webui Stored Cross-Site Scripting Vulnerability in File Upload Functionality
A stored cross-site scripting vulnerability has been identified in open-webui version 0.3.8. This issue arises in the chat file upload feature, where an attacker can inject malicious scripts into a file. When this file is accessed by a victim, either through a shared chat or a direct URL, the injected JavaScript is executed in the victim's browser. This vulnerability could lead to theft of user data, session hijacking, distribution of malware, and phishing attacks.
Open-WebUI Files Access Control Vulnerability Allowing Unauthorized View and Deletion of Files
A vulnerability in Open-WebUI version 0.3.8 allows attackers to bypass access controls and view or delete any files. The issue arises because the application does not verify if a user is an administrator. This flaw enables attackers to exploit the GET /api/v1/files/ endpoint to list all user-uploaded files, including their ID values. Subsequently, they can use the GET /api/v1/files/{file_id} endpoint to access information about specific files and the DELETE /api/v1/files/{file_id} endpoint to remove any file.
Open-WebUI Improper Access Control Vulnerability in Admin Chat Management
A vulnerability allowing improper access control has been identified in Open-WebUI version 0.3.8. This issue arises on the frontend admin page, where administrators are supposed to see only the chats of non-admin members. However, by altering the user_id parameter, it is possible to access the chats of any administrator, including those of other admin (owner) accounts.
Open-WebUI Improper Privilege Management Vulnerability Allowing Administrator Deletion
An improper privilege management vulnerability exists in Open-WebUI version 0.3.8. The application allows an admin user to delete other administrators through the API, despite this action being restricted in the user interface. The vulnerability arises because the API endpoint for user deletion does not properly enforce privilege checks, allowing admins to remove each other arbitrarily.
Open-WebUI Name Field Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Open-WebUI version 0.3.8. The issue allows an unauthenticated attacker to disrupt the Admin panel by entering excessively large text in the 'name' field during the sign-up process. This overloads the system, causing the Admin panel to become unresponsive and hindering administrators from managing users effectively, including actions like deleting, editing, or adding users. Additionally, authenticated users with low privileges can exploit this vulnerability to achieve the same disruptive effect in the Admin panel.
Open-WebUI Cross-Site Request Forgery Vulnerability Allowing Sensitive Actions via GET Requests
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Open-WebUI version 0.3.8. Sensitive actions, such as deleting and resetting data, are executed using the GET method. This allows attackers to exploit CSRF by tricking users into performing these actions unintentionally, simply by visiting a malicious site or through top-level navigation. The vulnerable endpoints include /rag/api/v1/reset, /rag/api/v1/reset/db, /api/v1/memories/reset, and /rag/api/v1/reset/uploads. This vulnerability affects the application's availability and integrity.
