CVE-2024-8026

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 20, 2025
Updated: Mar 26, 2025
CWE ID 352

Summary

CVE-2024-8026 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability affecting the netease-youdao/qanything project. This issue lies in the backend API, specifically in commit d9ab8bc. The server's overly permissive Cross-Origin Resource Sharing (CORS) headers allow all cross-origin requests, making it susceptible to CSRF attacks. This vulnerability poses a significant risk since it impacts all backend endpoints, enabling attackers to perform actions like creating, uploading, listing, deleting files, and managing knowledge bases.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share