Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PraisonAI before 4.6.78 Code Injection via API deployment generator
Vulnerability Description
PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
MervinPraison PraisonAI 代码注入漏洞
Vulnerability Description
MervinPraison PraisonAI是MervinPraison个人开发者的 MervinPraison PraisonAI 4.6.78之前版本存在代码注入漏洞,该漏洞源于未安全编码部署配置值,攻击者可通过deploy.api.host和agents_file配置参数注入任意Python表达式,这些表达式会在生成的服务器启动或处理请求时执行。
CVSS Information
N/A
Vulnerability Type
N/A