PT-2024-38000 · Unknown · Guardrails Ai

Natan Nehorai

·

Published

2024-07-21

·

Updated

2024-11-25

·

CVE-2024-6961

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Guardrails AI (affected versions not specified)
Description The issue concerns RAIL documents, an XML-based format used by Guardrails AI for enforcing formatting checks on LLM outputs. Users who consume RAIL documents from external sources are at risk of XML External Entity (XXE) attacks, which could lead to the leakage of internal file data through the SYSTEM entity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-6961
GHSA-F8HX-F4XW-C646

Affected Products

Guardrails Ai