#121·pdfGPT

通过固定的 `gradio==4.11.0` 读取未经验证的任意文件 CVE-2024-4941

作者: hamizan-azman创建于 2026年5月24日更新于 2026年5月24日
  1. Plant a target file outside any gradio allowlist (representing any sensitive file the pdfGPT process can read, e.g. /etc/passwd, ~/.env, ~/.AWS/credentials):

内容来源: bhaskatripathi/pdfGPT