Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
X-d Lab
X-d Lab langchain-chatglm-webui |
|
| CPEs | cpe:2.3:a:x-d_lab:langchain-chatglm-webui:2023-05-23:*:*:*:*:*:*:* | |
| Vendors & Products |
X-d Lab
X-d Lab langchain-chatglm-webui |
Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain Langchain-ai Langchain-ai langchain |
|
| Vendors & Products |
Langchain
Langchain langchain Langchain-ai Langchain-ai langchain |
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-732 | |
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-01T00:00:00.000Z
Updated: 2025-08-01T17:24:38.847Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45150
Updated: 2025-08-01T17:23:38.907Z
Status : Analyzed
Published: 2025-08-01T17:15:51.943
Modified: 2025-10-17T18:28:30.400
Link: CVE-2025-45150
No data.