Cross-Site Request Forgery Vulnerability in Vanna Web App by Vanna AI
CVE-2024-6841

6.5MEDIUM

Key Information:

Vendor

Vanna-ai

Vendor
CVE Published:
20 March 2025

What is CVE-2024-6841?

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Vanna Web App developed by Vanna AI, found in the latest commit. This vulnerability arises from the implementation of two SQL-related endpoints as simple GET requests, which makes them vulnerable to CSRF attacks. Attackers can exploit this flaw to execute arbitrary SQL commands without the user's intention to expose their web app. While the impact is mainly confined to data alteration or deletion, it highlights the need for enhanced security measures to protect user data and maintain the integrity of the web application.

Affected Version(s)

vanna-ai/vanna <= unspecified

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.