VYPR

Modeldb

by Vertaai

Source repositories

CVEs (2)

  • CVE-2024-1961HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this vulnerability to write arbitrary files anywhere in the file system by manipulating the 'artifact_path'…

  • CVE-2023-6023HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.03

    An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.