Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2xr-wvrv-p969

Опубликовано: 05 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

RAGAS has an Arbitrary File Read vulnerability

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.

Пакеты

Наименование

ragas

pip
Затронутые версииВерсия исправления

>= 0.2.3, < 0.3.0-rc1

0.3.0-rc1

EPSS

Процентиль: 17%
0.00054
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22
CWE-770
CWE-918

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 месяца назад

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.

CVSS3: 7.5
nvd
около 1 месяца назад

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.

EPSS

Процентиль: 17%
0.00054
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22
CWE-770
CWE-918