g4f is vulnerable to Authentication Bypass Using an Alternate Path or Channel
100
Critical Risk
Affected versions of this package are vulnerable to Authentication Bypass due to an improper access control configuration in the WebUI, where the primary /chat/ endpoint was not protected by the authentication mechanism, while sub-paths like /chat/test correctly enforced password checks. An attacker could exploit this vulnerability by directly navigating to the main chat endpoint to gain unauthorized access to the application's interface and functionality without requiring a password.
You are affected if you are using a version that falls within the vulnerable range.
g4f is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 0.3.9.0 - 0.6.0.2.
Upgrade the g4f library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant