Critical Path Traversal Found in h2oGPT
A path traversal flaw in h2oGPT versions 0.2.1 and earlier allows unauthenticated attackers to read, write, or delete files, potentially leading to RCE.
5 results for “path traversal”
A path traversal flaw in h2oGPT versions 0.2.1 and earlier allows unauthenticated attackers to read, write, or delete files, potentially leading to RCE.
Microsoft has patched a critical path traversal vulnerability in Kiota that allows malicious OpenAPI descriptions to inject unauthorized file references.
A path traversal vulnerability in Bold Reports Standalone Report Designer allows unauthenticated attackers to read sensitive files from the server.
A critical vulnerability in IBM Langflow OSS allows for arbitrary file writes due to improper input validation.
Progress confirms a high-severity flaw in Storage Zone Controllers necessitated a temporary service shutdown for customers.