2024-08-24 17:55:21 +00:00
### [CVE-2024-45190](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45190)


2025-09-29 16:08:36 +00:00

2024-08-24 17:55:21 +00:00
### Description
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request
### POC
#### Reference
- https://research.jfrog.com/vulnerabilities/mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605/
#### Github
No PoCs found on GitHub currently.