Intel

AIKIDO-2024-10197

haystack-ai is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2024-41950 Published Jul 29, 2024

40

Medium Risk

This Affects:

pythonhaystack-ai
2.0.0 - 2.3.0
Fixed in 2.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package allow Remote Code Execution (RCE) when using insecure Jinja templates.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges and when you are using unsecure Jinja templates.

Background info

haystack-ai is vulnerable to Remote Code Execution (RCE) in versions 2.0.0 - 2.3.0.

How to fix this

Upgrade the haystack-ai library to the patch version.