CVE-2024-6961

MEDIUM

Pypi Guardrails-ai < 0.5.0 - XXE

Title source: rule
STIX 2.1

Description

RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL documents from external sources are vulnerable to XXE, which may cause leakage of internal file data via the SYSTEM entity.

Scores

CVSS v3 5.9
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
pypi/guardrails-ai 0 - 0.5.0PyPI
Published Jul 21, 2024
Tracked Since Feb 18, 2026