Path traversal in Arduino Create Agent
CVE-2023-43802
7.1HIGH
What is CVE-2023-43802?
A security vulnerability has been discovered in the Arduino Create Agent, which affects the /upload endpoint that processes requests with the filename parameter. This flaw allows an unauthorized user with the capability to send HTTP requests to the local interface, or to circumvent CORS settings, to escalate their privileges to that of the user running the Arduino Create Agent service. The issue has been remedied in version 1.3.3, and users are strongly advised to update their installations promptly, as there are no known workarounds to mitigate this risk.
Affected Version(s)
arduino-create-agent < 1.3.3
