Server-Side Request Forgery Vulnerability in Vanna by vanna-ai
CVE-2024-8099

8.3HIGH

Key Information:

Vendor

Vanna-ai

Vendor
CVE Published:
20 March 2025

What is CVE-2024-8099?

A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in the Vanna product by vanna-ai when utilizing DuckDB as the database. This vulnerability allows attackers to exploit the application's ability to process crafted SQL queries that invoke DuckDB's default features. By leveraging functionalities such as read_csv, read_csv_auto, read_text, and read_blob, an attacker can make unauthorized requests to both internal and external resources. The exploitation of this flaw could lead to unauthorized access to sensitive data, internal systems, and potentially facilitate further attacks.

Affected Version(s)

vanna-ai/vanna <= unspecified

References

CVSS V3.0

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.