griptape is vulnerable to Command Injection
90
Critical Risk
Improper neutralization of special elements in OS command strings in Griptape CommandRunner allowed shell injection because commands were executed with subprocess.Popen(..., shell=True). An attacker able to influence command input could inject shell metacharacters such as pipes, redirects, or command chaining operators to execute unintended system commands. Successful exploitation could result in arbitrary command execution with the privileges of the running process.
You are affected if you are using a version that falls within the vulnerable range.
griptape is vulnerable to Command Injection in versions 0.27.0 - 1.9.4.
Upgrade the griptape library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant