VYPR
High severity7.2NVD Advisory· Published Nov 27, 2024· Updated Jun 17, 2026

CVE-2024-52959

CVE-2024-52959

Description

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:gss:iota_c.ai:*:*:*:*:*:*:*:*
    Range: >=1.0.0,<=2.1.3
  • Range: 1.0.0 - 2.1.3
  • Galaxy Software Services Corporation/iota C.ai Conversational Platformv5
    Range: 1.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.