CVE-2024-5334

Source
https://cve.org/CVERecord?id=CVE-2024-5334
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5334.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-5334
Published
2024-06-27T17:33:24Z
Modified
2026-09-18T03:30:35Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Local File Read in stitionai/devika
Details

A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by crafting a request with a malicious 'snapshot_path' parameter, leading to arbitrary file read from the system. This issue impacts the security of the application by allowing unauthorized access to sensitive files on the server.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "cwe_ids": [
        "CWE-73"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5334.json"
}
References

Affected packages

Git / github.com/stitionai/devika

Affected ranges

Type
GIT
Repo
https://github.com/stitionai/devika
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5334.json"