CRITICAL9.8
PYSEC-2024-262
Quick fix
PYSEC-2024-262 — agentscope: upgrade to the fixed version with the command below.
pip install --upgrade 'agentscope>=0.0.5a1'Details
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://gist.github.com/AfterSnows/0ad9d233a9d2a5b7e6e5273e2e23508d[EVIDENCE]
- https://rumbling-slice-eb0.notion.site/Unauthenticated-Remote-Code-Execution-via-The-use-of-eval-in-is_callable_expression-and-sanitize_nod-cd4ea6c576da4e0b965ef596855c298d[EVIDENCE]
- https://github.com/advisories/GHSA-6p55-qr3j-mpgq[ADVISORY]