Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2883 | An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. |
Github GHSA |
GHSA-w392-75q8-vr67 | Guardrails has an arbitrary code execution vulnerability |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 18 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Guardrailsai
Guardrailsai guardrails |
|
| CPEs | cpe:2.3:a:guardrailsai:guardrails:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Guardrailsai
Guardrailsai guardrails |
|
| Metrics |
ssvc
|
Wed, 18 Sep 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML files. If a victim user loads a maliciously crafted XML file containing Python code, the code will be passed to an eval function, causing it to execute on the user's machine. | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-18T17:45:44.580Z
Reserved: 2024-09-10T15:36:55.926Z
Link: CVE-2024-45858
Updated: 2024-09-18T17:45:37.986Z
Status : Deferred
Published: 2024-09-18T15:15:16.333
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-45858
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA