CVE-2024-56083
Published: 16 December 2024
Summary
CVE-2024-56083 is a high-severity Out-of-bounds Read (CWE-125) vulnerability in Ycombinator (inferred from references). Its CVSS base score is 8.1 (High).
Operationally, ranked at the 41.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-52974
Vulnerability details
Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer…
more
posts a screenshot of a Devin session to social media, or publicly streams their Devin session.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.