Vulnerability Details CVE-2024-11170
A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.4%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2024-11170
-
cpe:2.3:a:librechat:librechat:-
-
cpe:2.3:a:librechat:librechat:0.0.1
-
cpe:2.3:a:librechat:librechat:0.0.2
-
cpe:2.3:a:librechat:librechat:0.0.3
-
cpe:2.3:a:librechat:librechat:0.0.4
-
cpe:2.3:a:librechat:librechat:0.0.5
-
cpe:2.3:a:librechat:librechat:0.0.6
-
cpe:2.3:a:librechat:librechat:0.1.0
-
cpe:2.3:a:librechat:librechat:0.1.1
-
cpe:2.3:a:librechat:librechat:0.2.0
-
cpe:2.3:a:librechat:librechat:0.3.0
-
cpe:2.3:a:librechat:librechat:0.3.3
-
cpe:2.3:a:librechat:librechat:0.4.0
-
cpe:2.3:a:librechat:librechat:0.4.1
-
cpe:2.3:a:librechat:librechat:0.4.2
-
cpe:2.3:a:librechat:librechat:0.4.3
-
cpe:2.3:a:librechat:librechat:0.4.4
-
cpe:2.3:a:librechat:librechat:0.4.5
-
cpe:2.3:a:librechat:librechat:0.4.6
-
cpe:2.3:a:librechat:librechat:0.4.7
-
cpe:2.3:a:librechat:librechat:0.4.8
-
cpe:2.3:a:librechat:librechat:0.5.0
-
cpe:2.3:a:librechat:librechat:0.5.1
-
cpe:2.3:a:librechat:librechat:0.5.2
-
cpe:2.3:a:librechat:librechat:0.5.3
-
cpe:2.3:a:librechat:librechat:0.5.4
-
cpe:2.3:a:librechat:librechat:0.5.5
-
cpe:2.3:a:librechat:librechat:0.5.6
-
cpe:2.3:a:librechat:librechat:0.5.7
-
cpe:2.3:a:librechat:librechat:0.5.8
-
cpe:2.3:a:librechat:librechat:0.5.9
-
cpe:2.3:a:librechat:librechat:0.6.0
-
cpe:2.3:a:librechat:librechat:0.6.1
-
cpe:2.3:a:librechat:librechat:0.6.10
-
cpe:2.3:a:librechat:librechat:0.6.5
-
cpe:2.3:a:librechat:librechat:0.6.6
-
cpe:2.3:a:librechat:librechat:0.6.9
-
cpe:2.3:a:librechat:librechat:0.7.0
-
cpe:2.3:a:librechat:librechat:0.7.1
-
cpe:2.3:a:librechat:librechat:0.7.2
-
cpe:2.3:a:librechat:librechat:0.7.3
-
cpe:2.3:a:librechat:librechat:0.7.4