S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 10, 2024

CVE-2024-5334 Scanner

CVE-2024-5334 Scanner - Local File Inclusion vulnerability in Devika AI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by crafting a request with a malicious 'snapshot_path' parameter, leading to arbitrary file read from the system. This issue impacts the security of the application by allowing unauthorized access to sensitive files on the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
stitionai/devikaby stitionai
AFFECTED< -SAFE ✓≥ -
devikaby stitionai
0
Updated Sep 18, 2026View on NVD →
Detail

Devika AI is a web application used for web scraping and browser automation.

This vulnerability exists due to improper handling of user input in the snapshot_path parameter. An attacker can exploit this vulnerability to read arbitrary files on the system by crafting a malicious request.

The vulnerability is located in the /api/get-browser-snapshot endpoint of the Devika AI application. The snapshot_path parameter is not properly validated, allowing attackers to specify a path to a file they want to read.

Successful exploitation of this vulnerability could allow an attacker to read sensitive information from the server, such as configuration files or user data. This information could then be used to launch further attacks on the system.

References:

Solution Advice
  • Ensure input validation is implemented to prevent malicious file inclusions.
  • Use whitelists for allowed file paths.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.