CRITICAL9.8
GHSA-878h-rqcq-mv3x
Jan path traversal vulnerability
Details
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@janhq/core
Introduced in:
0No fixed version published yet for @janhq/core (npm). Pin to a known-safe version or switch to an alternative.