在 Google langfun 早于 0.1.2 的版本中,默认的 Python 协议中存在“动态评估代码中的指令未正确中和(Eval Injection)”漏洞。该漏洞允许远程未认证的攻击者通过精心构造的提示输入,诱导模型生成可执行的 Python 表达式;由于这些表达式在没有沙箱保护的情况下被直接评估,从而使得攻击者能够在宿主应用的上下文中执行任意 Python 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet