PT-2024-37182 · Devika · Devika
Published
2024-06-27
·
Updated
2025-07-15
·
CVE-2024-5820
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
stitutionai/devika version ecee79f
Description:
The issue arises from an unprotected WebSocket connection, allowing a malicious website to connect to the backend and issue commands on behalf of the user. This enables the malicious website to intercept all communication between the user and the backend, potentially leading to unauthorized command execution and server-side request forgery.
Recommendations:
For version ecee79f, consider restricting access to the WebSocket connection to prevent malicious websites from intercepting communication and issuing unauthorized commands. As a temporary workaround, disabling the WebSocket connection until a proper fix is implemented can help minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devika