CVE-2024-6841

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 352

Summary

CVE-2024-6841 is a newly identified Cross-Site Request Forgery (CSRF) vulnerability affecting the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app, which provide SQL functionality, are implemented as simple GET requests, making them susceptible to CSRF attacks. An attacker can exploit this vulnerability to run arbitrary SQL commands without the target's knowledge or consent, resulting in data alteration or deletion. The impact of this vulnerability is limited to the affected system, with the attacker unable to read query results.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share