Security: boxlite-ai/boxlite
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
allow_net hostname rules can be bypassed by connecting to an arbitrary IP with an allowed Host/SNIGHSA-c7v3-78jq-x45m published
Aug 26, 2026 by DorianZhengHigh -
Permission Bypass in boxlite Allows Modification of Read-Only FilesGHSA-g6ww-w5j2-r7x3 published
May 16, 2026 by DorianZhengCritical -
Timeout Bypass Vulnerability in boxliteGHSA-xjhv-pp2r-6f82 published
May 19, 2026 by DorianZhengModerate -
Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the HostGHSA-f396-4rp4-7v2j published
May 16, 2026 by DorianZhengCritical