Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39m5-v8xj-6c9r

Опубликовано: 24 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

EPSS

Процентиль: 100%
0.92895
Критический

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

EPSS

Процентиль: 100%
0.92895
Критический

9.1 Critical

CVSS3

Дефекты

CWE-22