📦 Qanything

by Youdao

🔍 What is Qanything?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10264

CRITICAL CVSS 9.8 Mar 20, 2025

CVE-2024-10264 is an HTTP request smuggling vulnerability in netease-youdao/qanything version 1.4.1 that allows attackers to bypass security controls by exploiting differences in how HTTP requests are...

CVE-2024-8024

HIGH CVSS 7.5 Mar 20, 2025

A CORS misconfiguration in netease-youdao/qanything version 1.4.1 allows attackers to bypass Same-Origin Policy protections, potentially exposing sensitive data from web applications. This affects any...

CVE-2024-12864

HIGH CVSS 7.5 Mar 20, 2025

An unauthenticated Denial of Service vulnerability exists in netease-youdao/qanything v2.0.0 where attackers can send file upload requests with excessively large filenames, overwhelming the server and...

CVE-2024-12866

HIGH CVSS 7.5 Mar 20, 2025

A local file inclusion vulnerability in netease-youdao/qanything v2.0.0 allows attackers to read arbitrary files on the file system. This can lead to sensitive data exposure including SSH keys, config...

CVE-2024-8027

MEDIUM CVSS 6.1 Mar 20, 2025

A stored Cross-Site Scripting vulnerability in netease-youdao/QAnything allows attackers to upload malicious knowledge files that execute arbitrary JavaScript when users interact with the chat interfa...