Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-55415

36
FAUCET Score

CVE-2024-55415 describes a path traversal vulnerability in DevDojo Voyager through version 1.8.0, specifically at the /admin/compass endpoint, affecting thecontrolgroup voyager product. This medium-severity vulnerability (CVSS 5.7) allows an authenticated attacker with low privileges to read arbitrary files, posing a high impact on confidentiality with low attack complexity. While not listed in KEV or Hot Lists, exploit intelligence indicates available Nuclei templates for arbitrary file read, and it has garnered significant community discussion and media coverage, including reports of a potential one-click RCE flaw.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.8.0CPE matchmatch criteria
cpe:2.3:a:thecontrolgroup:voyager:*:*:*:*:*:laravel:*:*

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
15.67%
Probability of exploitation in next 30 days
EPSS Percentile
96.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2024-55415 · Feb 5, 2025
This CVE's current EPSS score of 0.1567 is in the 99th percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-j63m-2vr6-fv7mhigh

DevDojo Voyager vulnerable to path traversal

Jan 30, 2025

References

github.com / thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php
Product
github.com / thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php
Product
sonarsource.com / blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities
ExploitThird Party Advisory