stitionai/devika main branch as of commit...
High severity
Unreviewed
Published
Aug 4, 2024
to the GitHub Advisory Database
•
Updated Aug 20, 2024
Description
Published by the National Vulnerability Database
Aug 4, 2024
Published to the GitHub Advisory Database
Aug 4, 2024
Last updated
Aug 20, 2024
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with
HarmBlockThreshold.BLOCK_NONE
forHarmCategory.HARM_CATEGORY_HATE_SPEECH
andHarmCategory.HARM_CATEGORY_HARASSMENT
insafety_settings
disables content protection. This allows malicious commands to be executed, such as reading sensitive file contents like/etc/passwd
.References