CVE-2025-4515

MEDIUM

Pribai Privategpt < 0.6.2 - Permissive CORS Policy

Title source: rule

Description

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the argument allow_origins leads to permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-942 CWE-697 CWE-346
Status published

Affected Products (1)

pribai/privategpt < 0.6.2

Timeline

Published May 10, 2025
Tracked Since Feb 18, 2026