CVE-2024-27320

HIGH

Refuel Autolabel <0.0.8 - RCE

Title source: llm
STIX 2.1

Description

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-95 CWE-1236
Status published
Products (2)
pypi/refuel-autolabel 0.0.8PyPI
refuel/autolabel 0.0.8
Published Sep 12, 2024
Tracked Since Feb 18, 2026