Логотип exploitDog
bind:CVE-2024-3098
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-3098

Количество 2

Количество 2

nvd логотип

CVE-2024-3098

почти 2 года назад

A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be exploited to bypass method restrictions and execute unauthorized code. The vulnerability is a bypass of the previously addressed CVE-2023-39662, demonstrated through a proof of concept that creates a file on the system by exploiting the flaw.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wvpx-g427-q9wc

почти 2 года назад

llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-3098

A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be exploited to bypass method restrictions and execute unauthorized code. The vulnerability is a bypass of the previously addressed CVE-2023-39662, demonstrated through a proof of concept that creates a file on the system by exploiting the flaw.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-wvpx-g427-q9wc

llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution

CVSS3: 9.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу