Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Unrestricted File Upload Leading to XSS in imartinez/privategpt
Vulnerability Description
A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
PrivateGPT 安全漏洞
Vulnerability Description
PrivateGPT是一个 AI 项目。 PrivateGPT 存在安全漏洞,该漏洞源于文件上传验证不当,攻击者利用该漏洞可以通过上传恶意 HTML 文件在用户浏览器会话的上下文中执行任意 JavaScript 代码。
CVSS Information
N/A
Vulnerability Type
N/A