CVE-2024-4343·Python vulnerability
A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/privategpt application, versions up to and including 0.3.0. The vulnerability arises due to the use of the `eval()` function to parse a string received from a remote AWS SageMaker LLM endpoint into a dictionary. This method of parsing is unsafe as it can execute arbitrary Python code contained within the response. An attacker can exploit this vulnerability by manipulating the response from the AWS SageMaker LLM endpoint to include malicious Python code, leading to potential execution of arbitrary commands on the system hosting the application. The issue is fixed in version 0.6.0.
- Severity
- critical
- Software
- Python
- Fixed in
- 0.6.0
- Published
- 2024-11-14
Affected versions
Until: 0.6.0
Fixed in: 0.6.0
How to fix this CVE
Upgrade the privategpt application to version 0.6.0 or later, which replaces the unsafe eval() function with secure JSON parsing in the SagemakerLLM component. If you are using privategpt through a Python package manager, update immediately and restart any services using the library. For systems running older versions, isolate AWS SageMaker endpoint communications through network segmentation until the patch can be applied.
sudo dnf update python3 && pip3 install --upgrade privategptDefensia detects this vulnerability
How to check if you are affected
- Check the installed privategpt version with: pip3 show privategpt | grep Version
- Verify the SagemakerLLM component is in use by searching your application configuration: grep -r 'SagemakerLLM' /path/to/privategpt/config/
- Search application logs for unusual Python code execution patterns: grep -i 'eval\|exec\|__import__' /var/log/application.log | grep -i sagemaker
- Confirm the patch was applied by checking the component file: grep -n 'json.loads\|ast.literal_eval' /path/to/privategpt/components/llm/custom/sagemaker.py
FAQ
What is CVE-2024-4343?
CVE-2024-4343 is a critical command injection vulnerability in privategpt's SagemakerLLM class that uses unsafe eval() to parse responses from AWS SageMaker endpoints, allowing attackers to execute arbitrary Python code by tampering with endpoint responses.
Is CVE-2024-4343 being actively exploited?
No, according to CISA's Known Exploited Vulnerabilities (KEV) catalog, CVE-2024-4343 is not currently being actively exploited in the wild, and no public exploits are available.
What versions of privategpt are affected by CVE-2024-4343?
All versions of privategpt up to and including 0.3.0 are affected; the vulnerability is fixed in version 0.6.0 and later.
How do I check if my server is vulnerable to CVE-2024-4343?
Run 'pip3 show privategpt' and verify the version is 0.6.0 or higher. If the version is 0.3.0 or earlier and your application uses SagemakerLLM, your system is vulnerable.
Does Defensia detect CVE-2024-4343?
Yes — Defensia's CVE advisory scanner compares installed Python package versions against the NVD database. If privategpt is installed on a monitored server, CVE-2024-4343 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-4343. Free for 1 server.
Get started free