Critical

db-gpt

Arbitrary File Write via RAG-Knowledge Endpoint

A vulnerability in version 0.6.0 of the software allows arbitrary file writes through the RAG-knowledge endpoint. This issue was patched in a subsequent release.

Available publicly on Nov 04 2024

9.1

CVSS:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Credit:

patrik-ha
Remediation Steps
  1. Update to the latest version of the software where this vulnerability has been patched.
  2. Ensure that user inputs are properly sanitized and validated, especially when dealing with file paths.
  3. Implement additional security measures such as restricting file write permissions and using secure coding practices to prevent similar vulnerabilities in the future.
Patch Details
  • Fixed Version: N/A
  • Patch Commit: N/A
Want more out of Sightline?

Sightline offers even more for premium customers

Go Premium

We have - related security advisories that are available with Sightline Premium.