CVE-2024-45989: Butterflyeffectpte Monica
Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server.
Affected products
- Butterflyeffectpte Monica: before 2.3.0 (fixed in 2.3.0)
Published 2024-09-26. Last modified 2026-06-17.