Pribai

Privategpt

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 10.05.2025 20:31:04
  • Zuletzt bearbeitet 08.07.2025 16:47:04

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the argument allow_origins leads to permissive cross-domain policy with untru...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 20.03.2025 10:11:34
  • Zuletzt bearbeitet 17.07.2025 16:02:22

A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit thi...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 20.03.2025 10:10:31
  • Zuletzt bearbeitet 15.07.2025 15:26:48

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process the...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 20.03.2025 10:09:21
  • Zuletzt bearbeitet 17.07.2025 15:56:07

An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijack...

Exploit
  • EPSS 2.75%
  • Veröffentlicht 14.11.2024 18:15:19
  • Zuletzt bearbeitet 17.07.2025 01:33:59

A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/privategpt application, versions up to and including 0.3.0. The vulnerability...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 27.06.2024 19:15:18
  • Zuletzt bearbeitet 19.05.2025 16:50:16

A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 27.06.2024 19:15:18
  • Zuletzt bearbeitet 17.07.2025 01:43:16

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 06.06.2024 19:16:05
  • Zuletzt bearbeitet 19.05.2025 16:49:21

A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that could result in unauthorized access to the local network and...

Exploit
  • EPSS 1.81%
  • Veröffentlicht 16.05.2024 09:15:14
  • Zuletzt bearbeitet 17.07.2025 20:01:01

imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can explo...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 16.05.2024 09:15:14
  • Zuletzt bearbeitet 19.05.2025 16:13:38

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScr...