GHSA-f8c8-4pm7-w885 · Severity: high · Ecosystem: pip — Cross-Site Request Forgery in CodeChecker API
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a logged in user, and use the web API with the same permissions, including but not limited to adding, removing or editing products. The attacker needs to know the ID of the available products to modify or delete them. The attacker cannot directly exfiltrate data (view) from CodeChecker, due to being limited to form-based CSRF. This issue affects CodeChecker: through 6.24.4.
Conclusion & alert: CVE-2024-53829 is rated High Exploit Risk (61.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.18%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-07 | 0.26% | 0.18% | -0.08% |
| 2 | 2026-03-01 | 0.06% | 0.26% | +0.21% |
| 3 | 2025-10-07 | — | 0.06% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 3.1 | HIGH |
|
2.8 | 4.7 | 85b1779b-6ecd-4f52-bcc5-73eac4659dcf |
GHSA-f8c8-4pm7-w885 · Severity: high · Ecosystem: pip — Cross-Site Request Forgery in CodeChecker API
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ericsson | codechecker | < 6.24.5 | cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Ericsson/codechecker/security/advisories/GHSA-f8c8-4pm7-w885 | Exploit Vendor Advisory |