PT-2024-21820 · Unknown · Refuel Autolabel Library

·

CVE-2024-27320

·

Published

2024-09-12

·

Updated

2026-07-07

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Refuel Autolabel library versions 0.0.8 and newer
Description An arbitrary code execution issue exists due to the way the Refuel Autolabel library handles provided CSV files in its classification tasks. If a maliciously crafted CSV file containing Python code is used to create a classification task, the code will be executed by an eval function.
Recommendations For Refuel Autolabel library versions 0.0.8 and newer, consider disabling the classification task feature that handles CSV files until a patch is available to prevent arbitrary code execution. Restrict the use of the eval function in classification tasks to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Eval Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-27320
GHSA-G2M8-F3X2-QPRW
PYSEC-2026-1870

Affected Products

Refuel Autolabel Library