CVE-2024-40422

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:stitionai:devika:1.0:*:*:*:*:*:*:*

History

29 Jan 2025, 22:15

Type Values Removed Values Added
References
  • () https://medium.com/@alpernae/uncovering-path-traversal-in-devika-v1-a-deep-dive-into-cve-2024-40422-f8ce81398b99 -

25 Jul 2024, 17:42

Type Values Removed Values Added
First Time Stitionai
Stitionai devika
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://github.com/stitionai/devika/pull/619 - () https://github.com/stitionai/devika/pull/619 - Exploit
References () https://github.com/stitionai/devika - () https://github.com/stitionai/devika - Product
References () https://github.com/alpernae/CVE-2024-40422 - () https://github.com/alpernae/CVE-2024-40422 - Third Party Advisory
CWE CWE-22
CPE cpe:2.3:a:stitionai:devika:1.0:*:*:*:*:*:*:*

24 Jul 2024, 17:12

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-24 16:15

Updated : 2025-01-29 22:15


NVD link : CVE-2024-40422

Mitre link : CVE-2024-40422


JSON object : View

Products Affected

stitionai

  • devika
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')