Vulnerabilities/

Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal

Severity:
High

Description

A vulnerability has been discovered in Agnai that permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of commands within those files. This issue could result in unauthorized access, full server compromise, data leakage, and other critical security threats.

Recommendation

Update the agnai package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
agnai
Anything's wrong? Let us know Last updated on November 26, 2024