Critical zero-day in popular AI API library exposed developer secrets
A critical flaw, CVE-2024-XXXX, in a widely used AI API library allows remote code execution and theft of API keys via environment variables. A patched version v2.4.1 was released within 24 hours; the library sees over 100,000 downloads per month.
- CVE-2024-XXXX enables remote code execution on unpatched systems
- Attack vector: malicious dependency or compromised CI/CD pipeline
- Patched version v2.4.1 released within 24 hours of the report
- The library gets over 100,000 downloads per month
Read next
Security