Insecure File Access in LangChain-ChatGLM-Webui by X-D-Lab
CVE-2025-45150

9.8CRITICAL

Key Information:

Vendor

X-D-Lab

Vendor
CVE Published:
1 August 2025

What is CVE-2025-45150?

The LangChain-ChatGLM-Webui application by X-D-Lab has a vulnerability due to insecure permissions, allowing attackers to gain unauthorized access to sensitive files. By crafting specific requests, attackers can view and download files that should be protected, potentially leading to information leaks and data compromise.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.