High severity8.8NVD Advisory· Published Oct 19, 2024· Updated Jun 17, 2026
CVE-2024-10131
CVE-2024-10131
Description
The add_llm function in llm_app.py in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input req['llm_factory'] and req['llm_name'] to dynamically instantiate classes from various model dictionaries. This approach allows an attacker to potentially execute arbitrary code due to the lack of comprehensive input validation or sanitization. An attacker could provide a malicious value for 'llm_factory' that, when used as an index to these model dictionaries, results in the execution of arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:infiniflow:ragflow:0.11.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:infiniflow:ragflow:0.11.0:*:*:*:*:*:*:*
- (no CPE)range: =0.11.0
- infiniflow/infiniflow/ragflowv5Range: unspecified
Patches
Vulnerability mechanics
References
1- huntr.com/bounties/42ae0b27-e851-4b58-a991-f691a437fbaanvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.