Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ragas 安全漏洞
Vulnerability Description
ragas是Vibrant Labs开源的一个优化和评估大语言模型的工具包。 ragas v0.2.3至v0.2.14版本存在安全漏洞,该漏洞源于对retrieved_contexts参数中的URL验证和清理不当,可能导致任意文件读取。
CVSS Information
N/A
Vulnerability Type
N/A