Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of commands within those files. This issue could result in unauthorized access, full server compromise, data leakage, and other critical security threats. This does not affect `agnai.chat`, installations using S3-compatible storage, or self-hosting that is not publicly exposed. This does affect publicly hosted installs without S3-compatible storage. Version 1.0.330 fixes this vulnerability.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Agnai
Agnai agnai |
|
CPEs | cpe:2.3:a:agnai:agnai:*:*:*:*:*:*:*:* | |
Vendors & Products |
Agnai
Agnai agnai |
|
Metrics |
ssvc
|
Thu, 26 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of commands within those files. This issue could result in unauthorized access, full server compromise, data leakage, and other critical security threats. This does not affect `agnai.chat`, installations using S3-compatible storage, or self-hosting that is not publicly exposed. This does affect publicly hosted installs without S3-compatible storage. Version 1.0.330 fixes this vulnerability. | |
Title | Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal | |
Weaknesses | CWE-35 CWE-434 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-26T17:11:42.815Z
Updated: 2024-09-26T18:23:22.262Z
Reserved: 2024-09-19T22:32:11.960Z
Link: CVE-2024-47169
Vulnrichment
Updated: 2024-09-26T17:37:34.915Z
NVD
Status : Analyzed
Published: 2024-09-26T18:15:10.157
Modified: 2024-10-30T18:25:39.783
Link: CVE-2024-47169
Redhat
No data.