{"id":"CVE-2024-5885","summary":"Server-Side Request Forgery (SSRF) in stangirard/quivr","details":"stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnerability could allow a malicious user to gain access to internal servers, the AWS metadata endpoint, and capture Supabase data.","modified":"2026-09-06T03:45:27.690480974Z","published":"2024-06-27T18:45:19.519Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5885.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/c178bf48-1d4a-4743-87ca-4cc8e475d274"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5885.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5885"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/The-Vibe-Company/quivr","events":[{"introduced":"f8693e223a31f845a41e9d81c3a93139c3c2527d"},{"last_affected":"f8693e223a31f845a41e9d81c3a93139c3c2527d"}],"database_specific":{"cpe":"cpe:2.3:a:quivr:quivr:0.0.236:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.0.236"},{"last_affected":"0.0.236"}],"source":"CPE_STRING"}}],"versions":["0.0.236","v0.0.236"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5885.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}