CVE-2024-5186

HIGH

privategpt 0.5.0 - Server-Side Request Forgery via File Upload Path Parameter

Title source: llm
STIX 2.1

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that could result in unauthorized access to the local network and potentially sensitive information. Specifically, by manipulating the 'path' parameter in a file upload request, an attacker can cause the application to make arbitrary requests to internal services, including the AWS metadata endpoint. This issue could lead to the exposure of internal servers and sensitive data.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
pribai/privategpt 0.5.0
Published Jun 06, 2024
Tracked Since Feb 18, 2026