In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade ramalama to version 0.8.3 or higher.
ramalama is a RamaLama is a command line tool for working with AI LLM models.
Affected versions of this package are vulnerable to Uncontrolled Search Path Element via the add_site_packages_to_syspath('/usr/local'), which unconditionally appended /usr/local/lib/python*/site-packages to sys.path. A local attacker can exploit the deprecated bin/ramalama launcher by placing a malicious Python module in the user-writable /usr/local directory.