Showing 3 vulnerabilities on this page for @janhq/core

Signals CISA KEV Ransomware Nuclei
npm vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Jan path traversal vulnerability

An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS9.8v3.1EPSS0.989%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jan path traversal vulnerability

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

CWE-434Jun 4, 20241 related artifact
CVSS9.8v3.1EPSS3.03%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Jan path traversal vulnerability

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

CWE-22CWE-31Jun 4, 20241 related artifact
CVSS7.5v3.1EPSS2.05%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX