The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 as a component of Exploit Intelligence
- lightspeed-core/rag-tool-cpu-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-cuda-12.9-rhel9 as a component of Lightspeed Core
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- Summary
- A flaw was found in Banks, a tool for generating LLM prompts. This vulnerability allows a remote attacker to achieve arbitrary code execution by injecting a malicious tool definition into a template. The system improperly resolves the path specified in this definition, enabling the attacker to import and run unauthorized code within the Banks application.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
