Vulnerabilities/

Jan path traversal vulnerability - @janhq/core

Severity:
High

Description

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. @janhq/core has been deprecated in favor of janhq/jan, this vulnerability has been patched there in v0.5.2.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@janhq/core
Anything's wrong? Let us know Last updated on July 17, 2024