Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

PlotAI eval vulnerability

GHSA-2hmp-5wqg-f24h · CVE-2025-1497 · PYSEC-2025-22

Published · Modified

Description

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. PlotAI commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk.

Ready to move

Start Securing

Free, no credit card | First findings in minutes