216.73.216.226

CVE-2025-1497

· Published 10/03/2025 14:15 · Modified 24/03/2025 18:46

Labels: CVE-2025-1497 2025-03-10CVE-2025-1497CWE-77[email protected]

Essential information

Published
10/03/2025 14:15
Modified
24/03/2025 18:46
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mljar / plotai cpe:2.3:a:mljar:plotai:*:*:*:*:*:*:*:*

References