Description
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit 068a2b08dc308c7ab4b569617f5fc8821237e3a0 https://github.com/firebase/firebase-tools/commit/068a2b08dc308c7ab4b569617f5fc8821237e3a0
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1772 | This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit 068a2b08dc308c7ab4b569617f5fc8821237e3a0 https://github.com/firebase/firebase-tools/commit/068a2b08dc308c7ab4b569617f5fc8821237e3a0 |
Github GHSA |
GHSA-rcm2-22f3-pqv3 | Firebase vulnerable to CRSF attack |
References
History
Tue, 22 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google firebase Command Line Interface |
|
| CPEs | cpe:2.3:a:google:firebase_command_line_interface:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Google
Google firebase Command Line Interface |
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-08-01T20:33:52.518Z
Reserved: 2024-04-24T09:25:02.333Z
Link: CVE-2024-4128
Updated: 2024-08-01T20:33:52.518Z
Status : Analyzed
Published: 2024-05-02T14:15:10.753
Modified: 2025-07-22T21:04:25.853
Link: CVE-2024-4128
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA