CVE-2023-40023

MEDIUM

yaklang < 1.2.4-sp1 - Local File Inclusion

Title source: llm
STIX 2.1

Description

yaklang is a programming language designed for cybersecurity. The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. This vulnerability allows attackers to include files from the server's local file system through the web application. When exploited, this can lead to the unintended exposure of sensitive data, potential remote code execution, or other security breaches. Users utilizing versions of the Yak Engine prior to 1.2.4-sp1 are impacted. This vulnerability has been patched in version 1.2.4-sp1. Users are advised to upgrade. users unable to upgrade may avoid exposing vulnerable versions to untrusted input and to closely monitor any unexpected server behavior until they can upgrade.

References (3)

Core 3
Core References

Scores

CVSS v3 6.5
EPSS 0.0092
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (6)
yaklang/yaklang 1.2.0 sp6 (3 CPE variants)
yaklang/yaklang 1.2.1 (10 CPE variants)
yaklang/yaklang 1.2.2 (8 CPE variants)
yaklang/yaklang 1.2.3 (4 CPE variants)
yaklang/yaklang 1.2.4
yaklang/yaklang 0 - 1.2.4-sp2Go
Published Aug 14, 2023
Tracked Since Feb 18, 2026