Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqmg-c2j8-fq92

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

InstructLab vulnerable to Path Traversal

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the logs_dir parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.

Пакеты

Наименование

instructlab

pip
Затронутые версииВерсия исправления

<= 0.26.1

Отсутствует

EPSS

Процентиль: 6%
0.00164
Низкий

7.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.1
redhat
4 месяца назад

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.

CVSS3: 7.1
nvd
3 месяца назад

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.

EPSS

Процентиль: 6%
0.00164
Низкий

7.1 High

CVSS3

Дефекты

CWE-22