Impact
The clear_plugin_cache scalar function in Anyquery accepts a caller‑controlled plugin name and passes it to path.Join before calling os.RemoveAll, without rejecting traversal segments. An attacker with a bearer‑token who can invoke the function via the /v1/query HTTP endpoint can supply a plugin string containing ".." segments that resolve to locations outside $XDG_CACHE_HOME/anyquery/plugins/. The resulting call to os.RemoveAll will recursively delete any reachable directory writable by the Anyquery server process, leading to permanent data loss and denial of service, with no disclosure of file contents.
Affected Systems
Anyquery, versions earlier than 0.4.5, deployed by the vendor julien040. Any installation that exposes the /v1/query endpoint with bearer-token authentication is susceptible.
Risk and Exploitability
The flaw carries a CVSS score of 7.3, indicating high impact. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation, and the issue is not listed in the CISA KEV catalog. Attackers holding a low‑privileged bearer token can invoke the vulnerable function over HTTP, making exploitation straightforward in exposed environments.
OpenCVE Enrichment
Github GHSA