deepspeed is vulnerable to Eval Injection
15
Low Risk
Affected versions of this package are vulnerable to eval injection in the BingBertSquad test script. This occurs because the script does not properly sanitize user input before passing it to the eval() function. As a result, an attacker can execute arbitrary code by injecting malicious input. This vulnerability allows attackers to take control of the application, potentially leading to unauthorized access, data breaches, or further exploitation of the underlying system.
You are affected if you are using a version which is within vulnerability ranges
deepspeed is vulnerable to Eval Injection in versions 0.1.0 - 0.15.4.
Upgrade the deepspeed library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant