📦 Privategpt

by Pribai

🔍 What is Privategpt?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-4343

CRITICAL CVSS 9.8 Nov 14, 2024

This CVE describes a critical command injection vulnerability in PrivateGPT's SageMaker integration that allows remote code execution. Attackers can manipulate responses from AWS SageMaker LLM endpoin...

CVE-2024-12063

HIGH CVSS 7.5 Mar 20, 2025

A Denial of Service vulnerability in imartinez/privategpt v0.6.2 allows attackers to crash the server by uploading files with excessively long filenames. This affects all users running the vulnerable ...

CVE-2024-8029

MEDIUM CVSS 6.1 Mar 20, 2025

This Cross-Site Scripting (XSS) vulnerability in PrivateGPT allows attackers to upload malicious SVG files that execute JavaScript when clicked by victims. This affects users of PrivateGPT version 0.5...

CVE-2024-5936

MEDIUM CVSS 6.1 Jun 27, 2024

An open redirect vulnerability in imartinez/privategpt version 0.5.0 allows attackers to redirect users to malicious websites by manipulating the 'file' parameter. This can lead to phishing attacks, m...

CVE-2024-3851

MEDIUM CVSS 5.4 May 16, 2024

A stored XSS vulnerability in the imartinez/privategpt repository allows attackers to upload malicious HTML files containing JavaScript payloads. When victims access these files, the JavaScript execut...