Insecure File Access in LangChain-ChatGLM-Webui by X-D-Lab
CVE-2025-45150
9.8CRITICAL
What is CVE-2025-45150?
The LangChain-ChatGLM-Webui application by X-D-Lab has a vulnerability due to insecure permissions, allowing attackers to gain unauthorized access to sensitive files. By crafting specific requests, attackers can view and download files that should be protected, potentially leading to information leaks and data compromise.