CVE-2024-3403

HIGH

PrivateGPT 0.2.0-0.5.9 - Local File Inclusion via File Upload Manipulation

Title source: llm
STIX 2.1

Description

imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI to retrieve or disclose the contents of any file on the system. This vulnerability could lead to various impacts, including but not limited to remote code execution by obtaining private SSH keys, unauthorized access to private files, source code disclosure facilitating further attacks, and exposure of configuration files.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0110
EPSS Percentile 61.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
pribai/privategpt 0.2.0 - 0.6.0
Published May 16, 2024
Tracked Since Feb 18, 2026