CVE-2024-40422
Last modified
CVE-2024-40422 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. EPSS estimates a 11.41% chance of exploitation in the next 30 days.
Description
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stitionai | Devika | 1.0 |
References
- https://github.com/alpernae/CVE-2024-40422Third Party Advisory
- https://github.com/alpernae/CVE-2024-40422Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-40422?
How severe is CVE-2024-40422?
How do I fix CVE-2024-40422?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40414A vulnerability in /goform/SetNetControlList in the sub_656B…9.8
- CVE-2024-40415A vulnerability in /goform/SetStaticRouteCfg in the sub_519F…9.8
- CVE-2024-40416A vulnerability in /goform/SetVirtualServerCfg in the sub_63…9.8
- CVE-2024-40417A vulnerability was found in Tenda AX1806 1.0.0.1. Affected …6.5
- CVE-2024-4042The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, …5.4
- CVE-2024-40420Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE…
- CVE-2024-40425File Upload vulnerability in Nanjin Xingyuantu Technology Co…9.8
- CVE-2024-40427Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows…7.9
- CVE-2024-4043The WP Ultimate Post Grid plugin for WordPress is vulnerable…6.4
- CVE-2024-40430Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-40431A lack of input validation in Realtek SD card reader driver …8.8
- CVE-2024-40432A lack of input validation in Realtek SD card reader driver …6.5
Are you affected by CVE-2024-40422?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
