Description
A vulnerability has been discovered in Agnai that permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to image file uploads to unauthorized or unintended directories, including overwriting of existing images which may be used for defacement.
Recommendation
Update the agnai package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.330
- Patched version(s): 1.0.330
References
Related Issues
- Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal - CVE-2024-47169
- `@backstage/backend-common` vulnerable to path traversal through symlinks - CVE-2024-26150
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
- Langchain Path Traversal vulnerability - CVE-2024-7774
You might also like:
- Tags:
- npm
- agnai
Anything's wrong? Let us know Last updated on November 26, 2024


