A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. PlotAI commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk.
{
"nvd_published_at": "2025-03-10T14:15:24Z",
"severity": "CRITICAL",
"github_reviewed": true,
"cwe_ids": [
"CWE-77",
"CWE-94"
],
"github_reviewed_at": "2025-03-10T22:21:12Z"
}