« Volver al listado

CVE-2024-41704

Estado: ModificadaCrítica (9.8)—

LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-41704",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-41704",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-23T19:30:40.956823Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:danny-avila:libre_chat:*:*:*:*:*:*:*:*"
          ],
          "vendor": "danny-avila",
          "product": "libre_chat",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "0.7.4-rc1"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-07-22T05:15:03.537",
  "references": [
    {
      "url": "https://github.com/danny-avila/LibreChat/discussions/3315#discussioncomment-10074284",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/danny-avila/LibreChat/pull/3363",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/realestate-com-au/vulnerability-disclosures/blob/main/LibreChat/CVE-2024-41704.md",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/danny-avila/LibreChat/discussions/3315#discussioncomment-10074284",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/danny-avila/LibreChat/pull/3363",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images."
    },
    {
      "lang": "es",
      "value": " LibreChat hasta 0.7.4-rc1 no valida las rutas de acceso normalizadas de las imágenes. (El trabajo en una versión fija comenzó en PR 3363.)"
    }
  ],
  "lastModified": "2026-06-17T07:48:05.013",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07976B79-F984-49AC-A56D-F3989BCB7916",
              "versionEndIncluding": "0.7.3"
            },
            {
              "criteria": "cpe:2.3:a:librechat:librechat:0.7.4:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92F06C4A-1DE2-4DB8-B652-7E920751ABCF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}