First published: Thu Mar 20 2025(Updated: )
A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing the server to become overwhelmed and unavailable to legitimate users.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
imartinez privategpt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12063 is classified as a Denial of Service (DoS) vulnerability.
To fix CVE-2024-12063, update the imartinez/privategpt application to the latest version that addresses this vulnerability.
CVE-2024-12063 is caused by improper handling of form-data with large filenames in the file upload feature.
CVE-2024-12063 affects users of imartinez/privategpt version v0.6.2.
CVE-2024-12063 primarily leads to Denial of Service, which may disrupt service availability but does not directly result in data loss.