CVE-2024-5549: Data leak through CORS misconfiguration in stitionai/devika

Published Jul 9, 2024
·
Updated

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability also enables attackers to perform actions on behalf of the user, such as deleting projects or sending messages. The issue arises from the lack of proper origin validation, allowing unauthorized cross-origin requests to be executed. The vulnerability is present in all versions of the repository, as no fixed version has been specified.

Affected Software

2 affected components
stitionai devika<=
stitionai devika=1.0

Event History

Jul 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-5549?

CVE-2024-5549 is considered a high-severity vulnerability due to its ability to expose sensitive user data.

2

How can I fix CVE-2024-5549?

To fix CVE-2024-5549, ensure proper CORS configurations are set to restrict access to only trusted origins.

3

What type of information can be stolen due to CVE-2024-5549?

CVE-2024-5549 allows attackers to steal sensitive information such as logs, browser sessions, and private API keys.

4

Who is affected by CVE-2024-5549?

CVE-2024-5549 affects users and applications utilizing the stitionai/devika repository.

5

What actions can attackers perform via CVE-2024-5549?

Attackers can perform actions on behalf of the user due to the CORS misconfiguration in CVE-2024-5549.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203