Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mage

First CVE: May 9, 2023Active for: 3 yearsTotal CVEs: 6

Mage's vulnerability footprint centers on its AI-driven workflow and data-pipeline orchestration platform, a niche but strategically positioned tool in machine-learning infrastructure. The vendor's recurring exposure spans authentication and access-control weaknesses—including path traversal, privilege assignment errors, session management flaws, and unauthenticated critical functions—alongside information disclosure risks, and vulnerabilities affecting this vendor skew toward serious outcomes. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mage over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2023
3 years ago
Most Recent CVE
Aug 23, 2024
700 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-31143CRITICAL
mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabl
May 9, 20239.829NONO
CVE-2024-45187HIGH
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute
Aug 23, 20248.825NONO
CVE-2024-45189MEDIUM
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Git Content" request
Aug 23, 20246.520NONO
CVE-2024-45190MEDIUM
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request
Aug 23, 20246.519NONO
CVE-2024-45188MEDIUM
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request
Aug 23, 20246.519NONO
CVE-2024-8072MEDIUM
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
Aug 22, 20245.317NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
17%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mage.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mage — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mage's Products

View all 2 CNAs →

Top CWEs