PyPi: Llama-Cpp-Python

CVE-2024-34359

Safety vulnerability ID: 70912

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at May 14, 2024 Updated at Dec 10, 2024
Scan your Python projects for vulnerabilities →

Advisory

Llama-cpp-python version 0.2.72 addresses a security issue by fixing a Remote Code Execution vulnerability caused by Server-Side Template Injection in Model Metadata.

Affected package

llama-cpp-python

Latest version: 0.3.5

Python bindings for the llama.cpp library

Affected versions

Fixed versions

Vulnerability changelog

- fix(security): Remote Code Execution by Server-Side Template Injection in Model Metadata by retr0reg in b454f40a9a1787b2b5659cd2cb00819d983185df
- fix(security): Update remaining jinja chat templates to use immutable sandbox by CISC in 1441

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application