Local File Read (LFI) by Prompt Injection via SnowFlake SQL in vanna-ai/vanna
Vulnerability Description
Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as `/etc/passwd`, by exploiting the exposed SQL queries through a Python Flask API.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8055
Credits & Attribution
No credits recorded in the NVD database.
More from vanna-ai
View All →Affected Vendor
vanna-ai
View all reports →