CVE-2024-27320

HIGH

Refuel Autolabel >= 0.0.8 - Remote Code Execution via Malicious CSV File

Title source: llm
STIX 2.1

Description

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 26.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-95 CWE-1236
Status published
Products (2)
pypi/refuel-autolabel 0.0.8PyPI
refuel/autolabel 0.0.8
Published Sep 12, 2024
Tracked Since Feb 18, 2026