Gladysassistant is an open-source home-automation and IoT-orchestration platform whose vulnerability profile centers on its core Gladys Assistant product and centers on path-traversal weaknesses in file-handling and directory-access logic. This reflects the product's role as a local service managing file operations across diverse smart-home integrations and datastores; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gladysassistant over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-47440MEDIUM Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensiti | Dec 7, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-43256MEDIUM A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input. | Sep 25, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gladysassistant.
Media articles that mention a CVE ID that affects a product developed by Gladysassistant — matched by CVE ID, not by vendor name.