datapizza-ai-core@0.0.21 vulnerabilities

Core components for the datapizza-ai framework

Direct Vulnerabilities

Known vulnerabilities in the datapizza-ai-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Neutralization of Special Elements Used in a Template Engine

datapizza-ai-core is a Core components for the datapizza-ai framework

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine via the ChatPromptTemplate() function that utilises Jinja2 Template. An attacker can execute arbitrary code or access sensitive information by injecting special elements into the template engine.

How to fix Improper Neutralization of Special Elements Used in a Template Engine?

There is no fixed version for datapizza-ai-core.

[0,)