CVE-2024-4181
Last modified
CVE-2024-4181 is a vulnerability of currently unknown severity. A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. EPSS estimates a 2.12% chance of exploitation in the next 30 days.
Description
A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Llamaindex | Llamaindex | >= 0.9.47, < 0.10.13 |
References
- https://huntr.com/bounties/1a204520-598a-434e-b13d-0d34f2a5ddc1Exploit, Third Party Advisory
- https://huntr.com/bounties/1a204520-598a-434e-b13d-0d34f2a5ddc1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4181?
How severe is CVE-2024-4181?
How do I fix CVE-2024-4181?
Are you affected by CVE-2024-4181?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
