VDB
Sign up
CRITICAL9.8

GHSA-878h-rqcq-mv3x

Jan path traversal vulnerability

Details

An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@janhq/core
Introduced in: 0

No fixed version published yet for @janhq/core (npm). Pin to a known-safe version or switch to an alternative.

References