What is CVE-2026-65700?
h2oGPT up to version 0.2.1 contains a path traversal vulnerability in its OpenAI-compatible files API, allowing unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by manipulating the bearer token. Users should immediately update to the latest version and restrict API access.
Azərbaycanca: h2oGPT-nin 0.2.1 versiyasına qədər olan OpenAI uyğun files API-sində path traversal zəifliyi mövcuddur. Bu, autentifikasiya olunmamış uzaqdan hücum edənə "bearer token" vasitəsilə server prosesinin əldə edə biləcəyi faylları oxumaq, yazmaq və silmək imkanı verir. İstifadəçilər dərhal proqramı ən son versiyaya yeniləməli və API girişini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of h2oGPT are affected by CVE-2026-65700?
h2oGPT versions up to 0.2.1 are affected by this vulnerability.
What operations can an attacker perform on the server using CVE-2026-65700?
An unauthenticated remote attacker can read, write, and delete arbitrary files accessible to the server process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.