CVE-2024-6583: Quivr

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.

Affected products

  • Quivr Quivr: version 0.0.254 only

Published 2025-03-20. Last modified 2026-06-17.