Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2024-53844] LabsAI’s EDDI Project Path Traversal

Summary

How XBOW autonomously found a path traversal in LabsAI's E.D.D.I. framework (CVE-2024-53844, fixed in 5.4): the /openapi spec led to a backup-import endpoint susceptible to file-system abuse.
Published
Collected

original ↗

Related coverage

back