llama-cpp-python@0.2.35 vulnerabilities

Python bindings for the llama.cpp library

Direct Vulnerabilities

Known vulnerabilities in the llama-cpp-python package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Server-side Request Forgery (SSRF)

llama-cpp-python is a Python bindings for the llama.cpp library

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through the __init__ constructor and __call__ method. An attacker can execute arbitrary code by injecting malicious templates into the chat template which is processed unsafely.

How to fix Server-side Request Forgery (SSRF)?

Upgrade llama-cpp-python to version 0.2.72 or higher.

[0.2.30,0.2.72)