Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hmp-5wqg-f24h

Опубликовано: 10 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

PlotAI eval vulnerability

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. PlotAI commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk.

Пакеты

Наименование

plotai

pip
Затронутые версииВерсия исправления

< 0.0.7

0.0.7

EPSS

Процентиль: 82%
0.01795
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.

EPSS

Процентиль: 82%
0.01795
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-94