CVE-2024-3924
Last modified
CVE-2024-3924 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a command for installing a software package. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a command for installing a software package. An attacker can exploit this by forking the repository, creating a branch with a malicious payload as the name, and then opening a pull request to the base repository. Successful exploitation could lead to arbitrary code execution within the context of the GitHub Actions runner. This issue affects versions up to and including v2.0.0 and was fixed in version 2.0.0.
Metrics
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| huggingface | huggingface/text-generation-inference | < 2.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-3924?
How severe is CVE-2024-3924?
How do I fix CVE-2024-3924?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-39226GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B130…9.8
- CVE-2024-39227GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B130…9.8
- CVE-2024-39228GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B130…9.8
- CVE-2024-39229An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT…5.3
- CVE-2024-3923The Beaver Builder – WordPress Page Builder plugin for WordP…5.4
- CVE-2024-39236Gradio v4.36.1 was discovered to contain a code injection vu…9.8
- CVE-2024-39241Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 all…6.1
- CVE-2024-39242A cross-site scripting (XSS) vulnerability in skycaiji v2.8 …6.1
- CVE-2024-39243An issue discovered in skycaiji 2.8 allows attackers to run …9.8
- CVE-2024-39248A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 a…5.4
- CVE-2024-39249Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular…7.5
- CVE-2024-3925The Element Pack Elementor Addons (Header Footer, Template L…5.4
Are you affected by CVE-2024-3924?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
