PT-2024-34989 · Unknown · Imartinez/Privategpt

Published

2024-06-06

·

Updated

2025-05-19

·

CVE-2024-5186

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions imartinez/privategpt version 0.5.0
Description A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of the software. This issue allows attackers to send crafted requests, potentially resulting in unauthorized access to the local network and sensitive information. By manipulating the path parameter in a file upload request, an attacker can cause the application to make arbitrary requests to internal services, including the AWS metadata endpoint. This could lead to the exposure of internal servers and sensitive data.
Recommendations For imartinez/privategpt version 0.5.0, as a temporary workaround, consider restricting access to the file upload section until a patch is available. Avoid using the path parameter in file upload requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-5186

Affected Products

Imartinez/Privategpt