1sealsemantic last-mile verification

Research / Finding

Fix RCE for canary exploit

F-PURPLELLAMA-003

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
meta-llama/PurpleLlamaReported fixmeta-llama/PurpleLlama

Fix RCE for canary exploit

Fixed in: public source commit; a separate fixed release is not established

fixed on main (release not confirmed)
details
Finding IDs
F-PURPLELLAMA-003
Status
fixed on main (release not confirmed)
Fixed in
public source commit; a separate fixed release is not established
Reported via
security contact
Note
The canary-exploit benchmark parsed model-response values with eval(), allowing input data to be evaluated as Python when that benchmark path ran. Commit 48fa920b of 11 March 2026 replaces those evaluations with ast.literal_eval() in verify_response.py. This confirms the recorded code/data-boundary change in public source, not a separately identified stable release or deployment. The existing finding is retained once, without adding another result for this recheck. A maintainer confirmation tying the patch to this report and public reporter credit remain unconfirmed.

F-PURPLELLAMA-003: Code / markup injection. Untrusted values reach eval instead of literal-only parsing. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-PURPLELLAMA-003

Security area (1seal assessment): Semantics. Replacing eval with literal parsing keeps model-response data from being interpreted as executable Python. Reviewed 26 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.