CRITICAL9.8
GHSA-qfjh-mvq6-c5p8
Jan path traversal vulnerability
Details
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. @janhq/core has been deprecated in favor of janhq/jan, this vulnerability has been patched there in v0.5.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@janhq/core
Introduced in:
0No fixed version published yet for @janhq/core (npm). Pin to a known-safe version or switch to an alternative.