CVE-2024-6583: Quivr
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.
Affected products
- Quivr Quivr: version 0.0.254 only
Published 2025-03-20. Last modified 2026-06-17.