PT-2025-12203 · Unknown · Imartinez/Privategpt
Published
2025-03-20
·
Updated
2025-07-15
·
CVE-2024-8018
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
imartinez/privategpt version 0.5.0
Description
A Denial of Service (DOS) attack can be performed by appending a large number of characters to the end of a multipart boundary when uploading a file. This leads to uncontrolled resource consumption, causing the system to become inaccessible and resulting in potential data inaccessibility and loss of productivity.
Recommendations
For imartinez/privategpt version 0.5.0, consider implementing a limit on the number of characters allowed in a multipart boundary to prevent excessive resource consumption. As a temporary workaround, restrict file uploads until a patch is available to mitigate the risk of exploitation.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imartinez/Privategpt