CVE-2024-41950
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone can create and render that template on the client machine they run any code. The vulnerability has been fixed with Haystack `2.3.1`.
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-1336
- NVD status
- Deferred
- Published
- 2024-07-31
CVE-2024-41950 at NVD
No indexed exploits for CVE-2024-41950 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-41950 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.