漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
letta-ai letta interface.py function_message eval injection
Vulnerability Description
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in dynamically evaluated code. The exploit has been disclosed to the public and may be used.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Vulnerability Title
letta-ai letta 安全漏洞
Vulnerability Description
Letta-ai letta是Letta-ai开源的一个具有内存、推理和上下文管理的有状态代理框架。 letta-ai letta 0.4.1及之前版本存在安全漏洞,该漏洞源于动态代码评估不当问题,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A