Aller au contenu

Fiche vulnérabilité

CVE-2024-52803 : faille critique hiyouga llama-factory (CVSS 9.8)

Description

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute arbitrary OS commands on the host system. The issue is caused by insecure usage of the `Popen` function with `shell=True`, coupled with unsanitized user input. Immediate remediation is required to mitigate the risk. This vulnerability is fixed in 0.9.1.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
21 nov. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • hiyouga llama-factory

Références

Rechercher une autre vulnérabilité dans la base CVE