LaVague 0.2.35 中的 存在远程代码执行漏洞,该函数会对源自网页内容的、不可信的语言模型输出进行求值。攻击者可以通过网页利用间接提示注入(indirect prompt injection)注入恶意的 Python 代码,从而在未经过审查的情况下,在操作者主机上执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lavague-ai | LaVague | ≤ 0.2.35 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| lavague-ai | LaVague | 0 ~ 0.2.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet