Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| gladys(npm) | 0 | N/A | N/A |
CVSS Metrics