CVE-2024-12866
Local File Inclusion in netease-youdao/qanything
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
netease-youdao · netease-youdao/qanythingWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →