PT-2024-23701 · Unknown · Llama Index

Published

2024-04-10

·

Updated

2024-04-10

·

CVE-2024-3098

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions llama index package (affected versions not specified)
Description A vulnerability was identified in the exec utils class of the llama index package, specifically within the safe eval function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be exploited to bypass method restrictions and execute unauthorized code. The vulnerability is a bypass of a previously addressed issue, demonstrated through a proof of concept that creates a file on the system by exploiting the flaw.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-3098
GHSA-WVPX-G427-Q9WC

Affected Products

Llama Index