CVE-2024-5827 POC (Proof-of-Concept)

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents ``. This can lead to command execution or the creation of backdoors.

Published: 2024-06-28

CVSS: 9.8

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Download CVE-2024-5827 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

Check my portfolio here:

https://tlncglobal.com/poc-141-cve-2025-49113/

https://tlncglobal.com/poc-727-cve-2024-55556/

https://tlncglobal.com/poc-62-cve-2025-6794/

https://tlncglobal.com/poc-262-cve-2025-3248/

https://tlncglobal.com/poc-336-cve-2025-26399/