Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Data leak through CORS misconfiguration in stitionai/devika
Vulnerability Description
A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability also enables attackers to perform actions on behalf of the user, such as deleting projects or sending messages. The issue arises from the lack of proper origin validation, allowing unauthorized cross-origin requests to be executed. The vulnerability is present in all versions of the repository, as no fixed version has been specified.
CVSS Information
N/A
Vulnerability Type
源验证错误
Vulnerability Title
Devika 访问控制错误漏洞
Vulnerability Description
Devika是Stition AI的一位高级 AI 软件工程师,可以理解高级人类指令,将它们分解为步骤,研究相关信息,并编写代码以实现给定的目标。 Devika存在访问控制错误漏洞,该漏洞源于通过CORS错误配置会导致数据泄漏。
CVSS Information
N/A
Vulnerability Type
N/A