PrivateGPT是一个 AI 项目。 PrivateGPT 0.5.0 版本存在输入验证错误漏洞,该漏洞源于对 file 参数处理不当,允许攻击者将用户重定向到由用户控制的输入指定的 URL,而无需进行适当的验证或清理。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| imartinez | imartinez/privategpt | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-5936.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet