Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.
Use CWE-918, Pi-Hole vendor hub and Pi-Hole product page to widen CVE-2024-34361 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-34087, CVE-2024-28247 and CVE-2021-32706 for nearby disclosures in the same product family.