Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3864-rp2m-2qfj | libre-chat Path Traversal vulnerability |
Wed, 27 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librechat
Librechat librechat |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:librechat:librechat:0.0.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Librechat
Librechat librechat |
|
| Metrics |
cvssV3_1
|
Mon, 25 Nov 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-27T16:35:53.218Z
Reserved: 2024-11-15T00:00:00.000Z
Link: CVE-2024-52787
Updated: 2024-11-27T16:35:45.763Z
Status : Deferred
Published: 2024-11-25T18:15:13.597
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52787
No data.
OpenCVE Enrichment
No data.
Github GHSA