PT-2025-5878 · Kanaries · Pygwalker

Published

2025-02-06

·

Updated

2025-02-06

·

CVE-2024-57609

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kanaries Inc Pygwalker versions prior to 0.4.9.9
Description The issue allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect path parameter of the login redirection function.
Recommendations For versions prior to 0.4.9.9, update to version 0.4.9.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the login redirection function or sanitizing the redirect path parameter to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-57609

Affected Products

Pygwalker