Path Traversal Vulnerability in h2oGPT Product by OpenAI
CVE-2026-65700
Key Information:
Badges
What is CVE-2026-65700?
The h2oGPT application, up to version 0.2.1, contains a vulnerability allowing unauthenticated attackers to exploit the OpenAI-compatible files API. By leveraging traversal sequences within the bearer token, attackers can bypass authentication mechanisms, leading to unauthorized file reading, writing, and deletion. This is facilitated through unsanitized input in the get_user_dir function, which improperly incorporates the bearer token into file paths. Consequently, attackers can manipulate file content, execute arbitrary code, and gain unauthorized control over the server's environment. Immediate remediation is essential to secure the affected product from these risks.
Affected Version(s)
h2ogpt 0 <= 0.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
