Skip to content

[Critical Security] Remote Code Execution (RCE) Vulnerability Detected #287

@devlin9824

Description

@devlin9824

Hello maintainers,

I am a security researcher and I have identified a Critical vulnerability (Remote Code Execution) in this repository. The vulnerability allows an attacker to execute arbitrary system commands on the server running optillm via specific inputs.

I have verified this with a working Proof of Concept (PoC).

To prevent potential exploitation by malicious actors, I have not included the technical details or the vulnerable module name in this public issue.

Action Requested: Please provide a private communication channel (email or GitHub Security Advisory) so I can share the full report and the PoC safely.

Best regards.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions