CVE Feed

    Dashboard / CVE / CVE-2024-5820

    CVE-2024-5820

    An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on behalf of the user. The backend serves all listeners on the given socket, enabling any such malicious website to intercept all communication between the user and the backend. This vulnerability can lead to unauthorized command execution and potential server-side request forgery.

    Published:Jun 27, 2024
    Last Modified:Jul 15, 2025
    EPS:Jun 27, 2024
    EPSS Score:0.00077
    CVSS Score:8.8

    Affected Products

    Vendor
    Stitionai
    Product
    Devika

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High