CVE-2025-45150

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:x-d_lab:langchain-chatglm-webui:2023-05-23:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-01 17:15

Updated : 2025-10-17 18:28


NVD link : CVE-2025-45150

Mitre link : CVE-2025-45150

CVE.ORG link : CVE-2025-45150


JSON object : View

Products Affected

x-d_lab

  • langchain-chatglm-webui
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource