An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
References
Link | Resource |
---|---|
https://github.com/jerryjliu/llama_index/issues/7054 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-08-15 17:15
Updated : 2023-08-22 17:32
NVD link : CVE-2023-39662
Mitre link : CVE-2023-39662
CVE.ORG link : CVE-2023-39662
JSON object : View
Products Affected
llamaindex_project
- llamaindex
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')