deepspeed is vulnerable to Eval Injection
15
Low Risk
Affected versions of this package are vulnerable to eval injection in the BingBertSquad test script. This occurs because the script does not properly sanitize user input before passing it to the eval() function. As a result, an attacker can execute arbitrary code by injecting malicious input. This vulnerability allows attackers to take control of the application, potentially leading to unauthorized access, data breaches, or further exploitation of the underlying system.
You are affected if you are using a version which is within vulnerability ranges
deepspeed is vulnerable to Eval Injection in versions 0.1.0 - 0.15.4.
Upgrade the deepspeed library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant