Local File Inclusion Vulnerability Affects Martinez's PrivateGPT v0.2.0
CVE-2024-3403
7.5HIGH
Summary
The imartinez/privategpt version 0.2.0 contains a local file inclusion vulnerability that permits attackers to read unauthorized files from the system’s filesystem. By exploiting the file upload functionality, malicious actors can influence the 'Search in Docs' feature or query the AI, enabling them to retrieve any file on the host. This vulnerability poses significant risks, including unauthorized access to sensitive data, potential remote code execution via exposure of private SSH keys, and the possibility of revealing source code and configuration files, which could facilitate further attacks.
Affected Version(s)
imartinez/privategpt <= unspecified
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved