Описание
Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.
EPSS
Процентиль: 18%
0.00057
Низкий
7.6 High
CVSS3
Дефекты
CWE-94
EPSS
Процентиль: 18%
0.00057
Низкий
7.6 High
CVSS3
Дефекты
CWE-94