CVE-2025-1497CRITICAL 9.8EPSS p56.7%

CVE-2025-1497CVE-2025-1497

Description

A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-generated output allows attacker to execute arbitrary Python code. Vendor commented out vulnerable line, further usage of the software requires uncommenting it and thus accepting the risk. The vendor does not plan to release a patch to fix this vulnerability.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.95% probability of exploitation · percentile 56.7% · 2026-06-19T12:03:05Z
Published2025-03-10
Last modified2025-10-03

Underlying weaknesses· 2

CWE-94CWE-77

References

  1. https://cert.pl/en/posts/2025/03/CVE-2025-1497
  2. https://cert.pl/posts/2025/03/CVE-2025-1497
  3. https://github.com/mljar/plotai
  4. https://github.com/mljar/plotai/commit/bdcfb13484f0b85703a4c1ddfd71cb21840e7fde

2

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in a Command ('Command Injection')cwe-770%live
WeaknessImproper Control of Generation of Code ('Code Injection')cwe-940%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-45146
CVE
CVE-2026-31236
CVE
CVE-2025-55319
CVE
CVE-2026-26020
CVE
CVE-2025-51482
CVE
CVE-2025-12345
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.