Sploitus

CVE-2024-10131

No indexed exploits for CVE-2024-10131 yet

The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate classes from various model dictionaries. This approach allows an attacker to potentially execute arbitrary code due to the lack of comprehensive input validation or sanitization. An attacker could provide a malicious value for 'llm_factory' that, when used as an index to these model dictionaries, results in the execution of arbitrary code.

Affected products
Ragflow
Infiniflow Ragflow
= 0.11.0
CVSS 3.1
8.8 HIGH
EPSS
1.1% (64th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2024-10-19
CVE-2024-10131 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-10131 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-10131 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.