Bounties
Partners
Community
Info
imartinez / privategpt
Project repository
Interact with your documents using the power of GPT, 100% privately, no data leaks
Submit a report
FIRST INTERACTION
WITHIN
29 DAYS
REVIEW
WITHIN
47 DAYS
FIX
WITHIN
259 DAYS
CORS Misconfiguration Vulnerability Leading to Sensitive Information Leak
Feb 15th 2025
superboy-zjc
•
pending
DoS by Sending Large Filename at File Upload Endpoint
Jan 5th 2025
mnqazi
•
High
•
$750
High
•
$750
•
CVE-2024-12063
CVE-2024-12063
Server Side Request Forgery using CVE-2024-4325
Sep 4th 2024
mnqazi
•
duplicate
High
Stored XSS via upload
Oct 15th 2024
web-hacker-team
•
Medium
•
$125
Medium
•
$125
•
CVE-2024-8029
CVE-2024-8029
DOS in multipart boundry while uploading the file
Sep 29th 2024
mnqazi
•
High
•
$750
High
•
$750
•
CVE-2024-8018
CVE-2024-8018
Open Redirect due to improper handling in file parameter
Jun 6th 2024
mnqazi
•
Medium
•
$125
Medium
•
$125
•
CVE-2024-5936
CVE-2024-5936
CSRF on delete all files.
Jun 10th 2024
mnqazi
•
Medium
•
$125
Medium
•
$125
•
CVE-2024-5935
CVE-2024-5935
Server Side Request Forgery (SSRF)
May 23rd 2024
mvlttt
•
High
•
$750
High
•
$750
•
CVE-2024-5186
CVE-2024-5186
Unrestricted file upload leads to XSS
Apr 16th 2024
hiu240900
•
Medium
•
$125
Medium
•
$125
•
CVE-2024-3851
CVE-2024-3851
Using eval() in sagemaker.py to load external AWS Sagemaker LLM request leading...
Nov 14th 2024
retr0reg
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-4343
CVE-2024-4343
Local File Inclusion
Apr 6th 2024
pinkdraconian
•
High
•
$750
High
•
$750
•
CVE-2024-3403
CVE-2024-3403
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0