Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead to command execution or the creation of backdoors.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 |
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-28T19:27:33.049Z
Updated: 2025-10-15T12:50:30.543Z
Reserved: 2024-06-10T23:46:32.719Z
Link: CVE-2024-5827
Updated: 2024-08-01T21:25:02.611Z
Status : Awaiting Analysis
Published: 2024-06-28T20:15:03.217
Modified: 2025-10-15T13:15:48.180
Link: CVE-2024-5827
No data.
ReportizFlow