CVE-2024-12866
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 22
Summary
CVE-2024-12866 is a local file inclusion vulnerability discovered in the netease-youdao/qanything software, specifically in version v2.0.0. This issue permits attackers to read arbitrary files on the affected system, posing a significant risk. By manipulating the inclusion of files, adversaries can potentially gain unauthorized access to private SSH keys, confidential files, source code, and configuration data, ultimately leading to remote code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.