PT-2024-38000 · Unknown · Guardrails Ai

·

CVE-2024-6961

·

Published

2024-07-21

·

Updated

2026-07-07

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Guardrails AI (affected versions not specified)
Description The issue concerns RAIL documents, an XML-based format used by Guardrails AI for enforcing formatting checks on LLM outputs. Users who consume RAIL documents from external sources are at risk of XML External Entity (XXE) attacks, which could lead to the leakage of internal file data through the SYSTEM entity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6961
GHSA-F8HX-F4XW-C646
PYSEC-2026-1431

Affected Products

Guardrails Ai