Description

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead to command execution or the creation of backdoors.

INFO

Published Date :

2024-06-28T19:27:33.049Z

Last Modified :

2025-10-15T12:50:30.543Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-5827 vulnerability.

Vendors Products
Vanna-ai
  • Vanna
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-5827.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact