VYPR
High severity7.5NVD Advisory· Published Aug 4, 2024· Updated Jun 17, 2026

CVE-2024-6331

CVE-2024-6331

Description

stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with HarmBlockThreshold.BLOCK_NONE for HarmCategory.HARM_CATEGORY_HATE_SPEECH and HarmCategory.HARM_CATEGORY_HARASSMENT in safety_settings disables content protection. This allows malicious commands to be executed, such as reading sensitive file contents like /etc/passwd.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Stitionai/Devika2 versions
    cpe:2.3:a:stitionai:devika:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:stitionai:devika:*:*:*:*:*:*:*:*range: >=2024-05-02
    • (no CPE)range: commit cdfb782b0e634b773b10963c8034dc9207ba1f9f
  • Range: BLOCK_NONE
  • stitionai/stitionai/devikav5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.