Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46430 | A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that could result in unauthorized access to the local network and potentially sensitive information. Specifically, by manipulating the 'path' parameter in a file upload request, an attacker can cause the application to make arbitrary requests to internal services, including the AWS metadata endpoint. This issue could lead to the exposure of internal servers and sensitive data. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 19 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pribai
Pribai privategpt |
|
| CPEs | cpe:2.3:a:pribai:privategpt:0.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Zylon
Zylon privategpt |
Pribai
Pribai privategpt |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 24 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zylon
Zylon privategpt |
|
| CPEs | cpe:2.3:a:zylon:privategpt:0.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Zylon
Zylon privategpt |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T21:03:11.037Z
Reserved: 2024-05-21T20:10:37.932Z
Link: CVE-2024-5186
Updated: 2024-08-01T21:03:11.037Z
Status : Analyzed
Published: 2024-06-06T19:16:05.860
Modified: 2025-05-19T16:49:21.883
Link: CVE-2024-5186
No data.
OpenCVE Enrichment
No data.
EUVD