← Back to browse · API

CVE-2024-36858

Severity
CRITICAL
CVSS
9.8
EPSS
0.03035
Risk score
40.26
CISA KEV
No
PoC
No
Published
2024-06-04
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-2143, GHSA-QFJH-MVQ6-C5P8
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-2143

Description

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

References