llama-stack@0.0.18 vulnerabilities

Llama Stack

Direct Vulnerabilities

Known vulnerabilities in the llama-stack package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Deserialization of Untrusted Data

llama-stack is a Llama Stack

Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the use of pickle as a serialization format for socket communication. An attacker can execute arbitrary code by sending maliciously crafted data that is deserialized.

How to fix Deserialization of Untrusted Data?

Upgrade llama-stack to version 0.0.41 or higher.

[,0.0.41)