Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pribai

First CVE: May 16, 2024Active for: 2 yearsTotal CVEs: 10
44.2
VTI Score
High

Pribai develops PrivateGPT, a specialized application for integrating language models with private data, whose vulnerability profile reflects the security challenges inherent to web-facing AI tooling and dynamic code generation. The recurring weakness classes—including cross-site scripting, resource exhaustion, cross-site request forgery, path traversal, and OS command injection—point to input-handling and access-control gaps typical of applications bridging user interfaces with system-level operations, while a meaningful share of disclosures reach serious severity. Live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pribai over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2024
2 years ago
Most Recent CVE
May 10, 2025
440 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5936MEDIUM
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users
Jun 27, 20246.142NOYES
CVE-2024-4343CRITICAL
A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/private
Nov 14, 20249.828NONO
CVE-2024-5186HIGH
A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requ
Jun 6, 20247.221NONO
CVE-2024-3403HIGH
imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upl
May 16, 20247.521NONO
CVE-2024-8018HIGH
A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the
Mar 20, 20257.520NONO
CVE-2024-12063HIGH
A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a
Mar 20, 20257.520NONO
CVE-2025-4515MEDIUM
A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the arg
May 10, 20256.518NONO
CVE-2024-8029MEDIUM
An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims cl
Mar 20, 20256.118NONO
CVE-2024-5935MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss
Jun 27, 20245.418NONO
CVE-2024-3851MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerabili
May 16, 20245.417NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
50%
40%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (50.0%)
Unknown0 (0.0%)
Required5 (50.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pribai.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pribai — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pribai's Products

View all 2 CNAs →

Top CWEs