{"id":"CVE-2023-47440","aliases":["GHSA-c79f-pqgf-fhp3"],"url":"https://o3.security/vulnerability/CVE-2023-47440","summary":"Directory Traversal in Gladys Assistant","details":"Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.","published":"2023-12-07T00:00:00Z","modified":"2026-07-15T01:48:51.223845323Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"gladys","fixedVersion":null}],"fix":{"url":"https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7","label":"GladysAssistant/Gladys#1918"},"references":[{"type":"WEB","url":"https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/47xxx/CVE-2023-47440.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-47440"},{"type":"ARTICLE","url":"https://blog.moku.fr/cve/"},{"type":"ARTICLE","url":"https://blog.moku.fr/cves/CVE-2023-47440/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:51.223845323Z"}}