A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code.
Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-7402 PlotAI eval vulnerability
Github GHSA Github GHSA GHSA-2hmp-5wqg-f24h PlotAI eval vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 03 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Mon, 12 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mljar
Mljar plotai
CPEs cpe:2.3:a:mljar:plotai:*:*:*:*:*:*:*:*
Vendors & Products Mljar
Mljar plotai
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 10 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Description A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.
Title Remote Code Execution in PlotAI
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-10-03T08:56:53.118Z

Reserved: 2025-02-20T13:19:59.176Z

Link: CVE-2025-1497

cve-icon Vulnrichment

Updated: 2025-05-12T15:34:41.219Z

cve-icon NVD

Status : Modified

Published: 2025-03-10T14:15:24.723

Modified: 2025-10-03T09:15:37.130

Link: CVE-2025-1497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.