GHSA-gprr-v9f2-px3c

Suggest an improvement
Source
https://github.com/advisories/GHSA-gprr-v9f2-px3c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-gprr-v9f2-px3c/GHSA-gprr-v9f2-px3c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gprr-v9f2-px3c
Aliases
  • CVE-2025-24986
Published
2025-03-11T18:32:18Z
Modified
2025-03-11T20:42:13.947171Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Azure PromptFlow remote code execution related to Jinja templates
Details

Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

Database specific
{
    "nvd_published_at": "2025-03-11T17:16:34Z",
    "cwe_ids": [
        "CWE-653"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-11T20:19:55Z"
}
References

Affected packages

PyPI / promptflow-tools

Package

Name
promptflow-tools
View open source insights on deps.dev
Purl
pkg:pypi/promptflow-tools

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.0

Affected versions

0.*

0.1.0b1
0.1.0b5
0.1.0b6
0.1.0b8
0.1.0b9
0.1.0b10
0.1.0b11
0.1.0b12
0.1.0b15

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0

PyPI / promptflow-core

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.17.2

Affected versions

0.*

0.1.0b1

1.*

1.8.0
1.9.0
1.10.0
1.10.1
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.15.0.post1
1.15.1
1.16.0
1.16.1
1.16.2
1.17.0
1.17.1