Intel

AIKIDO-2025-10157

smolagents is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 17, 2025

69

Medium Risk

This Affects:

PYTHONsmolagents
0.1.0 - 1.10.0
Fixed in 1.11.0
Are you affected? Scan for Free

TL;DR

Affected versions do not adequately validate executable functions or restrict dangerous modules when loading agents, which can lead to remote code execution (RCE). An attacker could exploit this weakness to execute arbitrary code, potentially compromising the system.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

smolagents is vulnerable to Remote Code Execution (RCE) in versions 0.1.0 - 1.10.0.

How to fix this

Upgrade the smolagents library to the patch version.