PT-2026-44540 · Unknown · Ai-Goofish-Monitor
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ai-goofish-monitor (affected versions not specified)
Description
An unauthenticated arbitrary file read issue exists in Windows deployments. Remote attackers can read arbitrary files by supplying absolute Windows paths or backslash-based traversal sequences to the 'GET /api/prompts/{filename}' endpoint. The flaw stems from an incomplete path traversal guard that only blocks forward slashes and '..', allowing the
os.path.join function to discard the intended prompts directory prefix when absolute paths are provided, thereby exposing files accessible to the application process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ai-Goofish-Monitor