CVE-2026-65700 | h2oai h2oGPT up to 0.2.1 OpenAI-compatible Files API backend_utils.py get_user_dir bearer_token path traversal
A vulnerability has been found in h2oai h2oGPT up to 0.2.1 and classified as critical. The impacted element is the function get_user_dir of the file openai_server/backend_utils.py of the component OpenAI-compatible Files API. The manipulation of the argument bearer_token leads to path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is listed as CVE-2026-65700. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More