CVE-2024-27321

HIGH

Refuel Autolabel <0.0.8 - RCE

Title source: llm
STIX 2.1

Description

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification task using a maliciously crafted CSV file containing Python code, the code will be passed to an eval function which executes it.

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 25.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-95 CWE-1236
Status published
Products (2)
pypi/refuel-autolabel 0.0.8PyPI
refuel/autolabel 0.0.8
Published Sep 12, 2024
Tracked Since Feb 18, 2026