chatgpt-web-midjourney-proxy icon indicating copy to clipboard operation
chatgpt-web-midjourney-proxy copied to clipboard

Access control bypass allows unauthorized file uploads to API/R2 buckets(访问控制权限绕过允许未授权文件上传至API/R2存储桶)

Open ithRSpoi opened this issue 6 months ago • 1 comments

Chatgpt-web-midjourney-proxy Version - 2.24.5

The website requires permission authentication to allow access, and the control console deletes the front-end restriction code

Image

In gpt-4-all, unauthorized users can upload files directly

POST /openapi/pre_signed POST /openapi/v1/upload Image Image Image Image Image

Access control bypass allows unauthorized file uploads to API/R2 buckets, which could be exploited maliciously to consume resources

ithRSpoi avatar May 27 '25 10:05 ithRSpoi