PT-2025-22863 · Unknown · Defog-Ai Introspect

Ybdesire

·

Publicado

2025-05-25

·

Atualizado

2025-06-03

·

CVE-2025-5151

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions defog-ai introspect versions up to 0.1.4
Description A critical vulnerability has been found in defog-ai introspect. This issue affects the execute analysis code safely function of the file introspect/backend/tools/analysis tools.py. The manipulation of the code argument leads to code injection. It is possible to launch the attack on the local host.
Recommendations For defog-ai introspect versions up to 0.1.4, apply the patch named 502 to fix this issue. As a temporary workaround, consider disabling the execute analysis code safely function until the patch is applied. Note that running this repository in a docker environment will significantly mitigate potential security risks.

Exploit

Correção

Code Injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-5151

Produtos afetados

Defog-Ai Introspect