The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Arbitrary Code Injection vulnerabilities in an interactive lesson.
Start learningUpgrade sentence-transformers to version 5.6.0 or higher.
sentence-transformers is a State-of-the-Art Text Embeddings
Affected versions of this package are vulnerable to Arbitrary Code Injection through the import_module_class function in sentence_transformers/util/misc.py due to a logic flaw that allows the security guard to be bypassed if a local path exists. An attacker can execute arbitrary code by placing malicious Python files in a model directory and influencing the loading process, even when the security flag is set to prevent such execution.