Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Link | Tags |
---|---|
https://huntr.dev/bounties/0631af48-84a3-4019-85db-f0f8b12cb0ab | patch exploit third party advisory issue tracking |
https://github.com/mintplex-labs/anything-llm/commit/3c88aec034934bcbad30c5ef1cab62cbbdb98e64 | patch |