PT-2025-12168 · Vanna · Vanna

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-6841

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions vanna-ai/vanna (affected versions not specified)
Description A Cross-Site Request Forgery (CSRF) issue exists in the vanna-ai/vanna repository. Two endpoints in the built-in web app, which provide SQL functionality, are implemented as simple GET requests, making them vulnerable to CSRF attacks. This allows an attacker to execute arbitrary SQL commands via CSRF without the target intending to expose the web app to the network or other users. The impact is limited to data alteration or deletion, as the attacker cannot read the results of the query.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6841

Affected Products

Vanna