CVE-2024-5821 - CVE House
Back to Database
Status published Medium CVE-2024-5821

Local File Inclusion (LFI) in stitionai/devika

Vulnerability Description

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5821

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stitionai/devika
Vulnerable Versions:
unspecified

Timeline

Official Publish: July 3rd, 2024
Last Modified: October 15th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)