PT-2025-22863 · Unknown · Defog-Ai Introspect

Ybdesire

·

Published

2025-05-25

·

Updated

2025-06-03

·

CVE-2025-5151

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions defog-ai introspect versions up to 0.1.4
Description A critical vulnerability has been found in defog-ai introspect. This issue affects the execute analysis code safely function of the file introspect/backend/tools/analysis tools.py. The manipulation of the code argument leads to code injection. It is possible to launch the attack on the local host.
Recommendations For defog-ai introspect versions up to 0.1.4, apply the patch named 502 to fix this issue. As a temporary workaround, consider disabling the execute analysis code safely function until the patch is applied. Note that running this repository in a docker environment will significantly mitigate potential security risks.

Exploit

Fix

Code Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5151

Affected Products

Defog-Ai Introspect