Critical Path Traversal Found in h2oGPT
A path traversal flaw in h2oGPT versions 0.2.1 and earlier allows unauthenticated attackers to read, write, or delete files, potentially leading to RCE.
3 results for “path-traversal”
A path traversal flaw in h2oGPT versions 0.2.1 and earlier allows unauthenticated attackers to read, write, or delete files, potentially leading to RCE.
Microsoft has patched a critical path traversal vulnerability in Kiota that allows malicious OpenAPI descriptions to inject unauthorized file references.
A critical vulnerability in IBM Langflow OSS allows for arbitrary file writes due to improper input validation.