Описание
Jan path traversal vulnerability
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. @janhq/core has been deprecated in favor of janhq/jan, this vulnerability has been patched there in v0.5.2.
Пакеты
Наименование
@janhq/core
npm
Затронутые версииВерсия исправления
<= 0.1.11
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
больше 1 года назад
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.