Critical severity9.8NVD Advisory· Published Mar 10, 2025· Updated Jun 17, 2026
CVE-2025-1497
CVE-2025-1497
Description
A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
plotaiPyPI | < 0.0.7 | 0.0.7 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/mljar/plotai/commit/bdcfb13484f0b85703a4c1ddfd71cb21840e7fdenvdPatchWEB
- cert.pl/en/posts/2025/03/CVE-2025-1497nvdThird Party AdvisoryWEB
- cert.pl/posts/2025/03/CVE-2025-1497nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-2hmp-5wqg-f24hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-1497ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/plotai/PYSEC-2025-22.yamlghsaWEB
News mentions
0No linked articles in our index yet.