Description
A vulnerability has been discovered in Agnai that permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to image file uploads to unauthorized or unintended directories, including overwriting of existing images which may be used for defacement.
Recommendation
Update the agnai package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.330
- Patched version(s): 1.0.330
References
Could your website be exposed too?
SmartScanner can check your website for Agnai vulnerable to Relative Path Traversal in Image Upload and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal - CVE-2024-47169
- `@backstage/backend-common` vulnerable to path traversal through symlinks - CVE-2024-26150
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
- Langchain Path Traversal vulnerability - CVE-2024-7774


