NA - CVE-2024-10267 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by...
NA - CVE-2024-10272 - lunary-ai/lunary is vulnerable to broken access...
lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the...
NA - CVE-2024-10273 - In lunary-ai/lunary v1.5.0, improper privilege...
In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have...
NA - CVE-2024-10274 - An improper authorization vulnerability exists...
An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms, allowing unauthorized users to access...
NA - CVE-2024-10275 - In version 1.5.5 of lunary-ai/lunary, a...
In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include...
NA - CVE-2024-10330 - In lunary-ai/lunary version 1.5.6, the...
In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This...
NA - CVE-2024-10359 - In danny-avila/librechat version v0.7.5-rc2, a...
In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an...
NA - CVE-2024-10361 - An arbitrary file deletion vulnerability exists...
An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation,...
NA - CVE-2024-10363 - In version 0.7.5 of danny-avila/LibreChat,...
In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break...
NA - CVE-2024-10366 - An improper access control vulnerability (IDOR)...
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided...