Agnai Chat System Vulnerability Could Lead to Sensitive Information Exposure
CVE-2024-47170

4.3MEDIUM

Key Information:

Vendor

Agnaistic

Status
Vendor
CVE Published:
26 September 2024

What is CVE-2024-47170?

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to sensitive information and exposure of confidential configuration files. This only affects installations with JSON_STORAGE enabled which is intended to local/self-hosting only. Version 1.0.330 fixes this issue.

Affected Version(s)

agnai < 1.0.330

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.