← Back

CVE-2024-21624

nvd nist
Published: Feb 9, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to a potential information leak (e.g., environment variables) in instances where developers utilize `MessageTemplate` and incorporate user-provided data into templates. The identified vulnerability has been remedied in pull request #2509 and will be included in versions released from 2.2.0. Users are strongly advised to upgrade to these patched versions to safeguard against the vulnerability. A temporary workaround involves filtering underscores before incorporating user input into the message template.

Affected (12)

Products: Nonebot: Nonebot
1 product
Nonebot
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Nonebot
From 2.0.1 to 2.2.0
Version 2.0.0
Version 2.0.0 alpha16
Version 2.0.0 beta1
Version 2.0.0 beta2
Version 2.0.0 beta3
Version 2.0.0 beta4
Version 2.0.0 beta5
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.0 rc4

References (4)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.