High severity7.2NVD Advisory· Published Nov 27, 2024· Updated Jun 17, 2026
CVE-2024-52959
CVE-2024-52959
Description
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 1.0.0 - 2.1.3
- Galaxy Software Services Corporation/iota C.ai Conversational Platformv5Range: 1.0.0
Patches
Vulnerability mechanics
References
1- zuso.ai/advisory/za-2024-12nvdThird Party Advisory
News mentions
0No linked articles in our index yet.