Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal
- Severity:
- High
Description
A vulnerability has been discovered in Agnai that permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaScript, enabling the execution of commands within those files. This issue could result in unauthorized access, full server compromise, data leakage, and other critical security threats.
Recommendation
Update the agnai package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.330
- Patched version(s): 1.0.330
References
- GHSA-mpch-89gm-hm83
- CVE-2024-47169
- CWE-22
- CWE-35
- CWE-434
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A4
- OWASP 2021-A6
Related Issues
- angular-base64-upload vulnerable to unauthenticated remote code execution - CVE-2024-42640
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Agnai vulnerable to Relative Path Traversal in Image Upload - CVE-2024-47171
- Angular Expressions - Remote Code Execution when using locals - CVE-2024-54152
You might also like:
- Tags:
- npm
- agnai
Anything's wrong? Let us know Last updated on November 26, 2024


