216.73.216.226

CVE-2024-5565

· Published 31/05/2024 15:15 · Modified 31/05/2024 19:14

Labels: CVE-2024-5565 2024-05-31CVE-2024-5565[email protected]

Essential information

Published
31/05/2024 15:15
Modified
31/05/2024 19:14
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the library’s “ask” method with "visualize" set to True (default behavior) leads to remote code execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References