CVE-2024-5936

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
27/06/2024
Last modified:
17/07/2025

Description

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerability includes potential phishing attacks, malware distribution, and credential theft.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pribai:privategpt:0.5.0:*:*:*:*:*:*:*