CVE-2024-10131

The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate classes from various model dictionaries. This approach allows an attacker to potentially execute arbitrary code due to the lack of comprehensive input validation or sanitization. An attacker could provide a malicious value for 'llm_factory' that, when used as an index to these model dictionaries, results in the execution of arbitrary code.
References
Link Resource
https://huntr.com/bounties/42ae0b27-e851-4b58-a991-f691a437fbaa Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:infiniflow:ragflow:0.11.0:*:*:*:*:*:*:*

History

01 Nov 2024, 17:12

Type Values Removed Values Added
CPE cpe:2.3:a:infiniflow:ragflow:0.11.0:*:*:*:*:*:*:*
First Time Infiniflow
Infiniflow ragflow
References () https://huntr.com/bounties/42ae0b27-e851-4b58-a991-f691a437fbaa - () https://huntr.com/bounties/42ae0b27-e851-4b58-a991-f691a437fbaa - Exploit, Third Party Advisory

22 Oct 2024, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.8

21 Oct 2024, 17:10

Type Values Removed Values Added
Summary
  • (es) La función `add_llm` en `llm_app.py` en infiniflow/ragflow versión 0.11.0 contiene una vulnerabilidad de ejecución remota de código (RCE). La función utiliza la entrada proporcionada por el usuario `req['llm_factory']` y `req['llm_name']` para instanciar dinámicamente clases de varios diccionarios de modelos. Este enfoque permite a un atacante ejecutar código arbitrario debido a la falta de una validación o desinfección integral de la entrada. Un atacante podría proporcionar un valor malicioso para 'llm_factory' que, cuando se utiliza como índice para estos diccionarios de modelos, da como resultado la ejecución de código arbitrario.

19 Oct 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-19 04:15

Updated : 2024-11-01 17:12


NVD link : CVE-2024-10131

Mitre link : CVE-2024-10131

CVE.ORG link : CVE-2024-10131


JSON object : View

Products Affected

infiniflow

  • ragflow
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')