CVE-2024-33865: Linqi

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.

Affected products

  • Linqi Linqi: before 1.4.0.1 (fixed in 1.4.0.1)

Published 2024-05-14. Last modified 2026-06-17.