Description

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled resource consumption can lead to prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.

INFO

Published Date :

2025-03-20T10:10:31.431Z

Last Modified :

2025-10-15T12:49:53.530Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8018 vulnerability.

Vendors Products
Imartinez
  • Imartinez Privategpt
Pribai
  • Privategpt
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-8018.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact