CVE-2024-6583

MEDIUM

stangirard/quivr - Path Traversal

Title source: llm

Description

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 34.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-23
Status published

Affected Products (1)

quivr/quivr

Timeline

Published Mar 20, 2025
Tracked Since Feb 18, 2026