CVE ID | CVE-2025-1497 |
Publication date | 10 March 2025 |
Vendor | MLJAR |
Product | PlotAI |
Vulnerable versions | All through 0.0.6 |
Vulnerability type (CWE) | Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in PlotAI software and participated in coordination of its disclosure.
The vulnerability CVE-2025-1497: Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.
Credits
We thank Eryk Winiarz for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.