Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jqh-3gj2-rj4v

Опубликовано: 30 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 3.3

Описание

A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 20%
0.00064
Низкий

4.8 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 3.3
nvd
10 месяцев назад

A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 20%
0.00064
Низкий

4.8 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-266