LavaGue: RCE via eval of LLM output derived from untrusted web content (Issue #650)
Security Advisory
#650
Critical
LavaGue
Affected:
- LavaGue (all versions prior to the fix in PR #651)
- LavaGue with Python extraction engine (core/retractors.py, python_engine.py, action_engine.py)
Fixed in:
- Version containing PR #651 (fix: prevent code execution in Python extraction output)
Referenced CVEs:
CVE-2026-85694 · 8.1
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.