Devika 漏洞列表
共找到 5 个与 Devika 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2024-40422: Devika v1 - Path Traversal POC
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system. -
CVE-2024-5334: Devika - Local File Inclusion POC
A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by crafting a request with a malicious 'snapshot_path' parameter, leading to arbitrary file read from the system. This issue impacts the security of the application by allowing unauthorized access to sensitive files on the server. -
CVE-2024-40422: Devika v1 - Path Traversal POC
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system. -
CVE-2024-5334: Devika - Local File Inclusion POC
A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by crafting a request with a malicious 'snapshot_path' parameter, leading to arbitrary file read from the system. This issue impacts the security of the application by allowing unauthorized access to sensitive files on the server. -
Devika v1 CVE-2024-40422 snapshot_path 目录遍历漏洞 无POC
Devika是stition开源的一个高级 AI 软件。Devika存在目录遍历漏洞。此漏洞是由于对snapshot_path参数校验不正确导致的。