PT-2025-12119 · Unknown · Imartinez/Privategpt

Published

2025-03-20

·

Updated

2025-07-17

·

CVE-2024-12063

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions imartinez/privategpt version v0.6.2
Description A Denial of Service (DoS) vulnerability exists in the file upload feature. The issue is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing the server to become overwhelmed and unavailable to legitimate users.
Recommendations For imartinez/privategpt version v0.6.2, implement stricter validation and sanitization of filenames during the file upload process to prevent excessively large filenames from being processed.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-12063

Affected Products

Imartinez/Privategpt