First published: Thu Jun 27 2024(Updated: )
A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Zylon PrivateGPT | =0.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5935 has a high severity due to its potential for data loss and service disruption.
To fix CVE-2024-5935, update to a patched version of imartinez/privategpt that addresses this CSRF vulnerability.
CVE-2024-5935 affects version 0.5.0 of the imartinez/privategpt application.
CVE-2024-5935 is a Cross-Site Request Forgery (CSRF) vulnerability.
An attacker exploiting CVE-2024-5935 could delete all uploaded files on the server, leading to significant data loss.