PT-2024-20041 · Unknown · Embedchain

Published

2024-01-21

·

Updated

2024-01-26

·

CVE-2024-23731

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Embedchain versions prior to 0.1.57
Description The issue allows attackers to execute arbitrary code, related to the yaml.load function argument in the openapi.py file.
Recommendations For versions prior to 0.1.57, update to version 0.1.57 or later to resolve the issue. As a temporary workaround, consider restricting the use of the yaml.load function in the openapi.py file until a patch is applied.

Fix

Argument Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23731
GHSA-RHHJ-5436-95VF
PYSEC-2024-7

Affected Products

Embedchain