Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Vulnerability Title
Guardrails 安全漏洞
Vulnerability Description
Guardrails是Guardrails AI开源的一个 Python 框架。 Guardrails 0.2.9至0.5.0及之前版本存在安全漏洞,该漏洞源于其验证XML文件的方式不当,如果受害者加载了包含恶意Python代码的XML文件,这些代码将被传递给eval函数并在此用户的机器上执行。
CVSS Information
N/A
Vulnerability Type
N/A