VYPR
Unrated severityNVD Advisory· Published Jul 24, 2024· Updated Jan 29, 2025

CVE-2024-40422

CVE-2024-40422

Description

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

Affected products

2
  • Stitionai/Devikacpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = v1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.