Remote Code Execution via unrestricted `eval()` in TruLens
Summary
TruLens calls Python's eval() builtin on the raw string returned by an LLM provider at src/feedback/trulens/feedback/llm_provider.py:2714. The intent is to parse a Python list literal, but eva
adithyanak.com3 min read