Haystack security advisories
2 advisories · none critical or high in 12 months · latest Jul 31, 2024
2 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 312024 | Insecure Jinja2 templates rendered in Haystack Components can lead to RCE CVE-2024-41950High7.5fixed in 2.3.1 | High7.5 | 2.3.1 |
| Mar 302023 | Use of hard-coded, security-relevant constants in deepset-ai/haystack CVE-2023-1712Critical9.8no fix yet | Critical9.8 | No fix yet |
About Haystack
The framework for RAG pipelines and agents.
Packages watched: haystack-ai (PyPI), farm-haystack (PyPI).