CVE-2024-6583

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.
CVSS

No CVSS.

References
Link Resource
https://huntr.com/bounties/c310b500-ec26-4121-8d3a-8e863181346f Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:quivr:quivr:0.0.254:*:*:*:*:*:*:*

History

15 Jul 2025, 15:55

Type Values Removed Values Added
CPE cpe:2.3:a:quivr:quivr:0.0.254:*:*:*:*:*:*:*
First Time Quivr quivr
Quivr
References () https://huntr.com/bounties/c310b500-ec26-4121-8d3a-8e863181346f - () https://huntr.com/bounties/c310b500-ec26-4121-8d3a-8e863181346f - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 15:55


NVD link : CVE-2024-6583

Mitre link : CVE-2024-6583


JSON object : View

Products Affected

quivr

  • quivr
CWE
CWE-23

Relative Path Traversal