CVE-2024-36857 is an arbitrary file read vulnerability affecting Jan v0.4.12, specifically through the /v1/app/readFileSync interface. Rated 7.5 HIGH, this vulnerability allows an unauthenticated attacker to read arbitrary files remotely with low attack complexity, potentially leading to significant information disclosure. While not currently on the CISA KEV list and with no reported active exploitation, public exploit templates exist, and its high EPSS score indicates a higher-than-average likelihood of exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.4.12CPE matchmatch criteria | cpe:2.3:a:homebrew:jan:0.4.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.