Description
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit  068a2b08dc308c7ab4b569617f5fc8821237e3a0 https://github.com/firebase/firebase-tools/commit/068a2b08dc308c7ab4b569617f5fc8821237e3a0
Published: 2024-05-02
Score: 2.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1772 This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit  068a2b08dc308c7ab4b569617f5fc8821237e3a0 https://github.com/firebase/firebase-tools/commit/068a2b08dc308c7ab4b569617f5fc8821237e3a0
Github GHSA Github GHSA GHSA-rcm2-22f3-pqv3 Firebase vulnerable to CRSF attack
History

Tue, 22 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google firebase Command Line Interface
CPEs cpe:2.3:a:google:firebase_command_line_interface:*:*:*:*:*:*:*:*
Vendors & Products Google
Google firebase Command Line Interface

Subscriptions

Google Firebase Command Line Interface
cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2024-08-01T20:33:52.518Z

Reserved: 2024-04-24T09:25:02.333Z

Link: CVE-2024-4128

cve-icon Vulnrichment

Updated: 2024-08-01T20:33:52.518Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T14:15:10.753

Modified: 2025-07-22T21:04:25.853

Link: CVE-2024-4128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses