CVE-2024-54909

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.

Published 2025-02-06. Last modified 2026-06-17.