PT-2024-36568 · Unknown · Vanna Library
Natan Nehorai
·
Published
2024-05-31
·
Updated
2024-11-25
·
CVE-2024-5565
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vanna library (affected versions not specified)
Description
The Vanna library is affected by a remote code execution issue due to prompt injection. This allows an attacker to alter the prompt function used for visualized results and run arbitrary Python code. The issue arises when external input is allowed to the library's
ask method with visualize set to True, which is the default behavior. This vulnerability has been reportedly exploited in the wild.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vanna Library