Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
Impact:
An RCE vulnerability has been identified in Microsoft Semantic Kernel Python SDK, specifically within theInMemoryVectorStore filter functionality.Patches:
The problem has been fixed in python-1.39.4. Users should upgrade this version or higher.Workarounds:
Avoid usingInMemoryVectorStore for production scenarios.