llmware.ai llmware是llmware.ai组织的一款助力企业构建大语言模型应用的产品。 llmware.ai llmware 0.4.6及之前版本存在SQL注入漏洞,该漏洞源于collection-database层(llmware/resources.py)中过滤器和查找值在未进行参数化或转义的情况下直接字符串插值到SQL WHERE子句,过滤器验证器仅检查键而不清理值,可能导致攻击者通过Library.block_lookup和Query.text_query_with_custom_
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| llmware-ai | llmware | ≤ 0.4.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| llmware-ai | llmware | 0 ~ 0.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet