Server-Side Request Forgery Vulnerability in Vanna by vanna-ai
CVE-2024-8099
8.3HIGH
What is CVE-2024-8099?
A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in the Vanna product by vanna-ai when utilizing DuckDB as the database. This vulnerability allows attackers to exploit the application's ability to process crafted SQL queries that invoke DuckDB's default features. By leveraging functionalities such as read_csv
, read_csv_auto
, read_text
, and read_blob
, an attacker can make unauthorized requests to both internal and external resources. The exploitation of this flaw could lead to unauthorized access to sensitive data, internal systems, and potentially facilitate further attacks.
Affected Version(s)
vanna-ai/vanna <= unspecified