CVE-2024-45489

CRITICAL

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to ...

Affects 0 products across 4 vendors.

BCS7.72
CVSS 3.19.8
EPSS1.2%
Percentile66th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-284: Improper Access Control

Software does not restrict or incorrectly restricts access to a resource.

Related Attack Patterns (CAPEC)
CAPEC-478 Modification of Windows Service Configuration
via CWE-284
CAPEC-479 Malicious Root Certificate
via CWE-284
CAPEC-546 Incomplete Data Deletion in a Multi-Tenant Environment
via CWE-284
CAPEC-550 Install New Service
via CWE-284
CAPEC-551 Modify Existing Service
via CWE-284
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2024-45489 affects Arc versions before 2024-08-26, allowing remote code execution in JavaScript boosts due to misconfigured Firebase ACLs.

BSID: BS-2024-GLOBAL-213440-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-45489?
CVE-2024-45489 affects Arc versions before 2024-08-26, allowing remote code execution in JavaScript boosts due to misconfigured Firebase ACLs.
What is the CVSS score for CVE-2024-45489?
CVE-2024-45489 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.2%.
Is CVE-2024-45489 actively exploited?
No confirmed active exploitation of CVE-2024-45489 as of 2026-05-30.
How do I remediate CVE-2024-45489?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-45489?
CVE-2024-45489 affects: Boost, Cannot, Cloud, Javascript.
Vulnerability Details
CVE IDCVE-2024-45489
BSIDBS-2024-GLOBAL-213440-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-09-20
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the victim's browser and runs arbitrary Javascript on that browser in a privileged context. NOTE: this is a no-action cloud vulnerability with zero affected users.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Attackers can create or update a boost using another user's ID, which installs the boost in the victim's browser and runs arbitrary JavaScript in a privileged context.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Boost —
Cannot —
Cloud —
Javascript —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 673 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash32c049bd1dafba70a5077225db4784bc6f39c5a6a06453c65f01bae68c090ff3fcce094f11e6e0ef6cb6b59d124bea86d516c27b2d8e5a9c8a8e98fdb6bc2766
Related CVEs affecting Boost
CVE-2026-7637 9.8 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versi... CVE-2024-31682 9.8 Incorrect access control in the fingerprint authentication mechanism of Phone... CVE-2016-9840 8.8 Siemens CADRA CVE-2023-38297 8.4 An issue was discovered in a third-party com.factory.mmigroup component, ship... CVE-2026-7252 8.1 The WP-Optimize – Cache, Compress images, Minify & Clean database to boost pa...
View all Boost CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →