Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-5936 PoC — PrivateGPT 输入验证错误漏洞

Source
Associated Vulnerability
Title:PrivateGPT 输入验证错误漏洞 (CVE-2024-5936)
Description:PrivateGPT是一个 AI 项目。 PrivateGPT 0.5.0 版本存在输入验证错误漏洞,该漏洞源于对 file 参数处理不当,允许攻击者将用户重定向到由用户控制的输入指定的 URL,而无需进行适当的验证或清理。
Description
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization.
File Snapshot

id: CVE-2024-5936 info: name: PrivateGPT < 0.5.0 - Open Redirect author: ctflearner severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.