Vulnerabilities/

Jan path traversal vulnerability

Severity:
High

Description

An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@janhq/core
Anything's wrong? Let us know Last updated on August 15, 2024