CVE-2024-10131
The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate classes from various model dictionaries. This approach allows an attacker to potentially execute arbitrary code due to the lack of comprehensive input validation or sanitization. An attacker could provide a malicious value for 'llm_factory' that, when used as an index to these model dictionaries, results in the execution of arbitrary code.
- Affected products
- Ragflow
- Infiniflow Ragflow
- = 0.11.0
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.1% (64th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2024-10-19
No indexed exploits for CVE-2024-10131 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-10131 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.