CVE-2024-8024: Youdao Qanything

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.

Affected products

  • Youdao Qanything: version 1.4.1 only

Published 2025-03-20. Last modified 2026-06-17.