A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.
History

Fri, 01 Aug 2025 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Youdao
Youdao qanything
CPEs cpe:2.3:a:youdao:qanything:2.0.0:*:*:*:*:*:*:*
Vendors & Products Youdao
Youdao qanything
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 20 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.
Title Local File Inclusion in netease-youdao/qanything
Weaknesses CWE-22
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-20T14:12:15.592Z

Reserved: 2024-12-20T19:06:26.066Z

Link: CVE-2024-12866

cve-icon Vulnrichment

Updated: 2025-03-20T14:12:12.653Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:30.840

Modified: 2025-08-01T01:14:38.343

Link: CVE-2024-12866

cve-icon Redhat

No data.