promptflow-evals is vulnerable to Remote Code Execution (RCE)
75
High Risk
Affected versions of the package are vulnerable to Remote Code Execution (RCE). This patch addresses two security issues: it replaces all uses of eval with ast.literal_eval to prevent arbitrary code execution during tool call parsing, and it fixes a vulnerability where crafted messages could inject unauthorized roles into the chat history.
You are affected if you are using a version that falls within the vulnerable range.
promptflow-evals is vulnerable to Remote Code Execution (RCE) in versions 0.3.0 - 0.3.4.
Upgrade the promptflow-evals library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant