CVE-2026-31236: The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to allow users to provide custom Python function d...
Added to the CISA Known Exploited Vulnerabilities catalog on 12 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.
The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to allow users to provide custom Python function definitions. However, the tool directly executes the provided code using the unsafe exec() function w...
Required action: Review and patch if applicable to your AI infrastructure.