Medium severity5.5NVD Advisory· Published Mar 1, 2024· Updated Jun 17, 2026
CVE-2024-2045
CVE-2024-2045
Description
Session version 1.17.5 allows obtaining internal application files and public
files from the user's device without the user's consent. This is possible
because the application is vulnerable to Local File Read via chat attachments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Session/Sessionv5Range: 1.17.5
Patches
Vulnerability mechanics
References
1- fluidattacks.com/advisories/newman/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.