mage-ai@0.9.30 vulnerabilities

Mage is a tool for building and deploying data pipelines.

Direct Vulnerabilities

Known vulnerabilities in the mage-ai package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Incorrect Privilege Assignment

mage-ai is a Mage is a tool for building and deploying data pipelines.

Affected versions of this package are vulnerable to Incorrect Privilege Assignment due to the incorrect privilege assignment to guest users who remain logged in after their accounts are deleted. An attacker can execute arbitrary code remotely by accessing the Mage AI terminal server.

How to fix Incorrect Privilege Assignment?

There is no fixed version for mage-ai.

[0,)
  • H
Directory Traversal

mage-ai is a Mage is a tool for building and deploying data pipelines.

Affected versions of this package are vulnerable to Directory Traversal via the Git Content request. An attacker with Viewer role can leak arbitrary files from the server by exploiting the path traversal vulnerability.

How to fix Directory Traversal?

There is no fixed version for mage-ai.

[0,)
  • H
Directory Traversal

mage-ai is a Mage is a tool for building and deploying data pipelines.

Affected versions of this package are vulnerable to Directory Traversal via the Pipeline Interaction request. An attacker with Viewer role can leak arbitrary files from the server by sending a crafted request.

How to fix Directory Traversal?

There is no fixed version for mage-ai.

[0,)
  • H
Path Traversal

mage-ai is a Mage is a tool for building and deploying data pipelines.

Affected versions of this package are vulnerable to Path Traversal via the File Content request. An attacker with Viewer permissions can leak arbitrary files from the server by exploiting insufficient validation of user-supplied input.

How to fix Path Traversal?

There is no fixed version for mage-ai.

[0,)
  • M
Information Exposure

mage-ai is a Mage is a tool for building and deploying data pipelines.

Affected versions of this package are vulnerable to Information Exposure through the terminal server command history retrieval process. An attacker can obtain sensitive information by exploiting the lack of proper access controls.

How to fix Information Exposure?

There is no fixed version for mage-ai.

[0,)