CVE-2024-6331: Injection by Prompt Injection in stitionai/devika
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with HarmBlockThreshold.BLOCKNONE for HarmCategory.HARMCATEGORYHATESPEECH and HarmCategory.HARMCATEGORYHARASSMENT in safetysettings disables content protection. This allows malicious commands to be executed, such as reading sensitive file contents like /etc/passwd.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6331?
CVE-2024-6331 has a severity rating that indicates a significant risk due to its potential for Local File Read (LFI) vulnerabilities.
How do I fix CVE-2024-6331?
To fix CVE-2024-6331, ensure you update StitionAI Devika to a version released after May 2, 2024, that addresses the vulnerability.
What systems are affected by CVE-2024-6331?
CVE-2024-6331 affects StitionAI Devika versions from May 2, 2024, onward, particularly those utilizing Google Gimini 1.0 Pro with specific settings.
What type of vulnerability is CVE-2024-6331?
CVE-2024-6331 is classified as a Local File Read (LFI) vulnerability that can be exploited through prompt injection.
Can CVE-2024-6331 be exploited remotely?
Yes, CVE-2024-6331 can be exploited remotely if the vulnerable version of StitionAI Devika is accessible over the internet.