CVE-2024-6583

MEDIUM

stangirard/quivr - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 48.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-23
Status published
Products (1)
quivr/quivr 0.0.254
Published Mar 20, 2025
Tracked Since Feb 18, 2026