Back

HIGH

Command Injection in run-llama/llama_index

Published May 16, 2024

Description

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published May 16, 2024
Updated Aug 1, 2024
Reserved Apr 25, 2024
CISA Vulnrichment
Updated May 16, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner @huntr_ai
Published May 16, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-1728 GHSA-PW38-XV9X-H8CH