PT-2026-57628 · Pypi · Self-Rag
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AkariAsai self-rag versions up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99
Description
An issue exists in the
retrieval lm component within the Indexer.deserialize from() function of the retrieval lm/src/index.py file. A remote attacker can trigger deserialization by manipulating the index meta.faiss argument. Deserialization is a process of converting a serialized format (like a byte stream) back into an object, which can lead to arbitrary code execution if the input is untrusted.Recommendations
As a temporary workaround, restrict access to the
Indexer.deserialize from() function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Self-Rag