Vanna v0.3.4 vulnerable to SQL injection in Flask Web APIs
CVE-2024-5827
9.8CRITICAL
Key Information
- Vendor
- Vanna-ai
- Status
- Vanna-ai/vanna
- Vendor
- CVE Published:
- 28 June 2024
Summary
Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead to command execution or the creation of backdoors.
Affected Version(s)
vanna-ai/vanna <= unspecified
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 9.8 - (CRITICAL)
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database