Arbitrary File Upload Vulnerability Affects Agnai Chat System
CVE-2024-47169

8.8HIGH

Key Information:

Vendor

Agnaistic

Status
Vendor
CVE Published:
26 September 2024

What is CVE-2024-47169?

The Agnai multi-user roleplaying chat system exhibits a significant vulnerability that allows attackers to upload arbitrary files to server-defined locations. This flaw, present in versions prior to 1.0.330, can be exploited to upload JavaScript files, which could result in executing malicious commands. The vulnerability poses severe risks, including unauthorized access to server resources, full server compromise, and potential leakage of sensitive data. Affected installations include those hosted publicly that do not utilize S3-compatible storage. The issue does not impact installations of agnai.chat, those using S3-Compatible storage, or self-hosted versions that are not accessible via the internet. The vulnerability has been addressed in version 1.0.330.

Affected Version(s)

agnai < 1.0.330

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.