PT-2026-82206 · Pypi · Langfun
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
langfun versions prior to 0.1.2
Description
An Eval Injection occurs in the default
lf.query Python protocol. This issue allows remote unauthenticated attackers to execute arbitrary Python code within the host application context. The flaw is triggered when crafted prompt inputs lead the model to generate executable Python expressions that are evaluated without a sandbox. Eval Injection is a flaw where untrusted input is passed to a code evaluation function, allowing the execution of unauthorized commands.Recommendations
Update langfun to version 0.1.2 or later.
As a temporary mitigation, restrict the use of the
lf.query protocol to prevent the evaluation of untrusted prompt inputs.Exploit
Fix
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langfun