Описание
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
Ссылки
- Permissions Required
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:lmsys:sglang:0.5.10:-:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00386
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-35
Связанные уязвимости
CVSS3: 9.1
github
3 месяца назад
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
EPSS
Процентиль: 31%
0.00386
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-35