CVE-2024-45187High· 7.1▾ TwilightMage AI incorrectly gives privileges to users with deleted accounts
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.5%
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server.
mage-ai <= 0.9.73Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-45188Medium· 6.5Mage AI Path Traversal vulnerability
CVE-2024-45189Medium· 6.5Mage AI Path Traversal vulnerability
CVE-2024-8072Medium· 5.3Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
CVE-2024-45190Medium· 6.5Mage AI Path Traversal vulnerability