Quivr is a focused AI-powered search and knowledge-management application that exposes a narrow but structurally significant attack surface around web-based data handling. Its documented vulnerabilities center on input-validation and request-handling weaknesses—server-side request forgery, cross-site scripting, and relative path traversal—that are characteristic of applications bridging user input to backend services and file systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quivr over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5885HIGH stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing | Jun 27, 2024 | 8.6 | 24 | NO | NO |
CVE-2024-4851HIGH A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerabilit | Jun 6, 2024 | 7.7 | 22 | NO | NO |
CVE-2024-6229MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affecting the latest version. Users can upload files via URL, which | Jul 7, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-6583MEDIUM A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipul | Mar 20, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quivr.
Media articles that mention a CVE ID that affects a product developed by Quivr — matched by CVE ID, not by vendor name.