A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files. | |
Title | Local File Inclusion in netease-youdao/qanything | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:31.785Z
Updated: 2025-03-20T14:12:15.592Z
Reserved: 2024-12-20T19:06:26.066Z
Link: CVE-2024-12866

Updated: 2025-03-20T14:12:12.653Z

Status : Received
Published: 2025-03-20T10:15:30.840
Modified: 2025-03-20T10:15:30.840
Link: CVE-2024-12866

No data.