PT-2025-20641 · Unknown · Zylon Privategpt

Gavin Zhong

+1

·

Published

2025-05-10

·

Updated

2025-05-10

·

CVE-2025-4515

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zylon PrivateGPT versions up to 0.6.2
Description A problematic issue was found in Zylon PrivateGPT, affecting an unknown part of the file settings.yaml. The manipulation of the allow origins argument leads to a permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely.
Recommendations For Zylon PrivateGPT versions up to 0.6.2, as a temporary workaround, consider restricting the allow origins argument to trusted domains until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2025-4515

Affected Products

Zylon Privategpt