CVE-2024-34524 Information
May 08, 2024
cve
Description
In XLANG OpenAgents through fe73ac4 the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.
Reference
https://github.com/xlang-ai/OpenAgents/issues/112 https://github.com/xlang-ai/OpenAgents/blob/880e26adfe380e999962fc645fc8fc80bd72f103/backend/utils/utils.py#L31
Share on: