CVE-2025-4515

MEDIUM

Pribai Privategpt < 0.6.2 - Permissive CORS Policy

Title source: rule
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the argument allow_origins leads to permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-942 CWE-697 CWE-346
Status published
Products (1)
pribai/privategpt < 0.6.2
Published May 10, 2025
Tracked Since Feb 18, 2026