CVE-2024-34524 Information

Description

In XLANG OpenAgents through fe73ac4 the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.

Reference

https://github.com/xlang-ai/OpenAgents/issues/112 https://github.com/xlang-ai/OpenAgents/blob/880e26adfe380e999962fc645fc8fc80bd72f103/backend/utils/utils.py#L31

Share on: