mage-ai vulnerabilities
CVEs whose affected-version data names the mage-ai package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2024-45188Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45187High· 7.1Mage AI incorrectly gives privileges to users with deleted accounts
Mage AI incorrectly gives privileges to users with deleted accounts
▾ Twilightmage-ai · mage-aiEPSS 0.50%via OSV
CVE-2024-45189Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
▾ Sunlitmage-ai · mage-aiEPSS 0.88%via OSV
CVE-2024-45190Medium· 6.5Mage AI Path Traversal vulnerability
Mage AI Path Traversal vulnerability
▾ Sunlitmage-ai · mage-aiEPSS 0.86%via OSV
CVE-2024-8072Medium· 5.3Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
▾ Sunlitmage-ai · mage-aiEPSS 0.60%via OSV