CVE-2024-6583
MEDIUMstangirard/quivr - Path Traversal
Title source: llmDescription
A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.
Scores
CVSS v3
4.3
EPSS
0.0014
EPSS Percentile
34.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-23
Status
published
Affected Products (1)
quivr/quivr
Timeline
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026