mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-05 10:17:57 +00:00
1.1 KiB
1.1 KiB
CVE-2024-6331
Description
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with HarmBlockThreshold.BLOCK_NONE
for HarmCategory.HARM_CATEGORY_HATE_SPEECH
and HarmCategory.HARM_CATEGORY_HARASSMENT
in safety_settings
disables content protection. This allows malicious commands to be executed, such as reading sensitive file contents like /etc/passwd
.
POC
Reference
No PoCs from references.