PT-2025-12212 · Snowflake+3 · Snowflake+3
Published
2025-03-20
·
Updated
2025-03-20
·
CVE-2024-8055
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vanna version 0.6.3
Description
The issue allows unauthenticated remote users to read arbitrary local files on the victim server by exploiting exposed SQL queries through a Python Flask API. This is achieved via SQL injection in the Snowflake database, specifically in file staging operations using the
PUT and COPY commands.Recommendations
For Vanna version 0.6.3, consider restricting access to the Snowflake database and limiting the use of the
PUT and COPY commands until a patch is available. As a temporary workaround, review and modify the Python Flask API to prevent SQL injection attacks.Fix
SQL injection
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Python
Python Flask Api
Snowflake
Vanna