Local File Read (LFI) by Prompt Injection via Postgres SQL in vanna-ai/vanna
Vulnerability Description
vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, including sensitive files like `/etc/passwd`, by exploiting the exposed SQL queries via a Python Flask API.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5753
Credits & Attribution
No credits recorded in the NVD database.
More from vanna-ai
View All →Affected Vendor
vanna-ai
View all reports →