We've discovered a vulnerability in which attackers could forge HTTP requests to manipulate the charm data directory to access or delete anything on the server. This has been patched in https://github.com/charmbracelet/charm/commit/3c90668f955c7ce5ef721e4fc9faee7053232fd3 and is available in release v0.12.1. We recommend that all users running self-hosted charm instances update immediately.
This vulnerability was found in-house and we haven't been notified of any potential exploiters.
If you have any questions or comments about this advisory:
Charm热爱开源 • Charm loves open source
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2022-05-24T20:55:22Z",
"nvd_published_at": "2022-05-07T04:15:00Z",
"severity": "CRITICAL"
}