{"id":"GHSA-q5mg-pc7r-r8cr","summary":"Files or Directories Accessible to External Parties in ProjectDiscovery","details":"Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login.","aliases":["CVE-2024-5262","GO-2024-2907"],"modified":"2026-07-17T21:05:14.690497452Z","published":"2024-06-05T06:30:39Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-06-05T17:06:29Z","nvd_published_at":"2024-06-05T04:15:11Z","cwe_ids":["CWE-552"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5262"},{"type":"WEB","url":"https://github.com/projectdiscovery/interactsh/pull/874"},{"type":"WEB","url":"https://github.com/projectdiscovery/interactsh/commit/6a0cb98b16636a98712729f3d23e34d8bf7260e7"},{"type":"PACKAGE","url":"https://github.com/projectdiscovery/interactsh"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2907"},{"type":"WEB","url":"https://zuso.ai/advisory/za-2024-01"}],"affected":[{"package":{"name":"github.com/projectdiscovery/interactsh","ecosystem":"Go","purl":"pkg:golang/github.com/projectdiscovery/interactsh"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-q5mg-pc7r-r8cr/GHSA-q5mg-pc7r-r8cr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}