Command Injection Vulnerability in JinaAI's RunGpt Framework Could Lead to Full Control Over Client Machines
CVE-2024-4181
8.8HIGH
What is CVE-2024-4181?
A command injection vulnerability exists within the Llama_Index library, particularly in the RunGptLLM class, which is utilized by JinaAI's RunGpt framework. This flaw stems from improper handling of the eval function, potentially enabling a malicious or compromised hosting provider to execute arbitrary commands on the client’s machine. Such exploitation poses a significant risk, potentially allowing the hosting provider to gain full control over client systems. This issue was addressed in Llama_Index version 0.10.13, underscoring the importance of updating to mitigate risks associated with this vulnerability.
Affected Version(s)
run-llama/llama_index < 0.10.13