Vulnerability library
Security checkNovember 26, 2024

Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmagnai

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A vulnerability has been discovered in Agnai that permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of commands within those files. This issue could result in unauthorized access, full server compromise, data leakage, and other critical security threats.

Recommendation

Update the agnai package to the latest compatible version. Followings are version details:

  • Affected version(s): < 1.0.330
  • Patched version(s): 1.0.330

References

Could your website be exposed too?

SmartScanner can check your website for Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated November 26, 2024