Bounties
Partners
Community
Info
netease-youdao / qanything
Project repository
Question and Answer based on Anything.
Submit a report
FIRST INTERACTION
WITHIN
33 DAYS
REVIEW
WITHIN
33 DAYS
FIX
WITHIN
90 DAYS
Cross-Site Scriptting in bot chat
Dec 20th 2024
aboutbo
•
duplicate
Medium
Server-side request forgery
Jan 13th 2025
aboutbo
•
not applicable
Arbitrary file upload vulnerability lead to remote command execute in netease-yo...
Jan 16th 2025
passer6y
•
duplicate
Critical
Local File Inclusion in netease-youdao/qanything
Jan 14th 2025
eggdkk
•
High
High
•
CVE-2024-12866
CVE-2024-12866
Unauthenticated DoS by Sending Large Filename at File Upload Endpoint
Jan 12th 2025
mnqazi
•
High
•
$450
High
•
$450
•
CVE-2024-12864
CVE-2024-12864
SQL Injection
Oct 14th 2024
tuna18dv
•
duplicate
Critical
HTTP Request Smuggling
Nov 3rd 2024
srivallikusumba
•
High
•
$450
High
•
$450
•
CVE-2024-10264
CVE-2024-10264
Stored XSS while using the malicious document as reference to chat
Oct 23rd 2024
mnqazi
•
duplicate
Critical
CSRF allows to Delete everything, including the conversation, Knowledge Base, up...
Oct 22nd 2024
mnqazi
•
duplicate
High
SQL injection in delete_files in both master and qanything-python branch
Oct 17th 2024
0gur1
•
duplicate
High
XSS stored in conversation
Oct 17th 2024
7resp4ss
•
Medium
•
$75
Medium
•
$75
•
CVE-2024-8027
CVE-2024-8027
SQL Injection in /api/local_doc_qa/delete_files
Oct 17th 2024
7resp4ss
•
duplicate
High
SQL Injection
Oct 13th 2024
mvlttt
•
Critical
•
$1440
Critical
•
$1440
•
CVE-2024-7099
CVE-2024-7099
CSRF lead to create/rename/delete knowledge_base and upload/delete docs/weblink
Oct 12th 2024
fewword
•
duplicate
High
CSRF lead to create/update/delete bots
Oct 12th 2024
fewword
•
duplicate
Critical
Data Handling in stream_requests
Aug 20th 2024
syed-ghufran-hassan
•
informative
Medium
store xss from CVE-2024-4367 in pdf.js
Oct 10th 2024
tianstcht
•
not applicable
CORS misconfiguration
Oct 9th 2024
mvlttt
•
High
•
$450
High
•
$450
•
CVE-2024-8024
CVE-2024-8024
CSRF due to overly permissive CORS headers for backend API
Oct 9th 2024
patrik-ha
•
High
•
$450
High
•
$450
•
CVE-2024-8026
CVE-2024-8026
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0