{"id":"CVE-2024-5935","summary":"CSRF Vulnerability in imartinez/privategpt","details":"A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.","modified":"2026-08-12T03:30:37.006902427Z","published":"2024-06-27T18:45:51.085Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-352"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5935.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/b374f1c9-fa25-4b52-a34d-5153afd5a295"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5935.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5935"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zylon-ai/private-gpt","events":[{"introduced":"94ef38cbba8fe5e406eb192efafe774b9aadb564"},{"last_affected":"94ef38cbba8fe5e406eb192efafe774b9aadb564"}],"database_specific":{"cpe":"cpe:2.3:a:pribai:privategpt:0.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.5.0"},{"last_affected":"0.5.0"}],"source":"CPE_STRING"}}],"versions":["0.5.0","v0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-5935.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"}]}