VendorsStitionaidevika1.0
Vulnerabilities

Stitionai Devika 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-40422
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.
Published 2024-07-24 · Modified
9.11 PoCEPSS 0.113
CVE-2024-5820
Unprotected WebSocket in stitionai/devika
Published 2024-06-27 · Analyzed
8.8EPSS 0.008
CVE-2024-5549
Data leak through CORS misconfiguration in stitionai/devika
Published 2024-07-09 · Analyzed
8.1EPSS 0.003
CVE-2024-5712
CSRF Vulnerability in stitionai/devika
Published 2024-06-28 · Analyzed
8.1EPSS 0.003
CVE-2024-5334
Local File Read in stitionai/devika
Published 2024-06-27 · Analyzed
7.5EPSS 0.021
CVE-2024-5548
Directory Traversal in stitionai/devika
Published 2024-06-27 · Analyzed
7.5EPSS 0.010
CVE-2024-5547
Directory Traversal in stitionai/devika
Published 2024-06-27 · Analyzed
7.5EPSS 0.010