PT-2025-12168 · Vanna · Vanna
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-6841
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
vanna-ai/vanna (affected versions not specified)
Description
A Cross-Site Request Forgery (CSRF) issue exists in the vanna-ai/vanna repository. Two endpoints in the built-in web app, which provide SQL functionality, are implemented as simple GET requests, making them vulnerable to CSRF attacks. This allows an attacker to execute arbitrary SQL commands via CSRF without the target intending to expose the web app to the network or other users. The impact is limited to data alteration or deletion, as the attacker cannot read the results of the query.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vanna