0.0.79.post1
1 years ago
1 years ago
Known vulnerabilities in the llama-hub package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
llama-hub is an A library of community-driven data loaders for LLMs. Use with LlamaIndex and/or LangChain. Affected versions of this package are vulnerable to Arbitrary Code Injection due to insecure YAML parsing via the How to fix Arbitrary Code Injection? Upgrade | [,0.0.67) |
llama-hub is an A library of community-driven data loaders for LLMs. Use with LlamaIndex and/or LangChain. Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection') via the OpenAPI and ChatGPT plugin loaders. An attacker can execute arbitrary code because How to fix Improper Control of Generation of Code ('Code Injection')? Upgrade | [,0.0.67) |