nemoguardrails@0.6.1 vulnerabilities

NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.

Direct Vulnerabilities

Known vulnerabilities in the nemoguardrails package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Directory Traversal

nemoguardrails is a NeMo Guardrails is an open-source toolkit for easily adding programmagle guardrails to LLM-based conversational systems.

Affected versions of this package are vulnerable to Directory Traversal via the _get_rails function, due to improper sanitization of config_ids. An attacker can exploit this vulnerability by adding dangerous characters or sequences in config_ids.

How to fix Directory Traversal?

Upgrade nemoguardrails to version 0.9.1 or higher.

[,0.9.1)