漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
Vulnerability Description
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Vulnerability Title
PPTAgent 安全漏洞
Vulnerability Description
PPTAgent是ICIP-CAS开源的一款基于大模型的智能演示文稿生成工具。 PPTAgent 418491a之前版本存在安全漏洞,该漏洞源于Python eval函数对LLM生成代码的执行问题,可能导致任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A