First published: Sat May 10 2025(Updated: )
A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the argument allow_origins leads to permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zylon PrivateGPT | <=0.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4515 is classified as problematic due to its impact on cross-domain policy.
To fix CVE-2025-4515, ensure that the 'allow_origins' argument in settings.yaml is configured to restrict access only to trusted domains.
CVE-2025-4515 affects Zylon PrivateGPT versions up to and including 0.6.2.
CVE-2025-4515 is a cross-domain policy vulnerability that allows permissive access to untrusted domains.
Yes, CVE-2025-4515 can potentially lead to exploitation by allowing unauthorized requests from untrusted sources.