Axolotl 0.18.0 及之前版本在 multipack 补丁路径中存在一个远程代码执行(RCE)漏洞。该漏洞的根源在于 的默认值被设为 而非 ,导致安全机制被绕过。攻击者可以通过构造一个恶意的 Hugging Face 模型仓库并将其选为 来触发该漏洞;该仓库在通过 加载时,会以硬编码的 方式被读取,从而使攻击者能够执行任意的 Python 代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| axolotl-ai-cloud | axolotl | ≤ 0.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| axolotl-ai-cloud | axolotl | 0 ~ 0.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet