Логотип exploitDog
bind:CVE-2024-52803
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52803

Количество 2

Количество 2

nvd логотип

CVE-2024-52803

около 1 года назад

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute arbitrary OS commands on the host system. The issue is caused by insecure usage of the `Popen` function with `shell=True`, coupled with unsanitized user input. Immediate remediation is required to mitigate the risk. This vulnerability is fixed in 0.9.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hj3w-wrh4-44vp

около 1 года назад

LLama Factory Remote OS Command Injection Vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-52803

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute arbitrary OS commands on the host system. The issue is caused by insecure usage of the `Popen` function with `shell=True`, coupled with unsanitized user input. Immediate remediation is required to mitigate the risk. This vulnerability is fixed in 0.9.1.

CVSS3: 7.5
2%
Низкий
около 1 года назад
github логотип
GHSA-hj3w-wrh4-44vp

LLama Factory Remote OS Command Injection Vulnerability

CVSS3: 7.5
2%
Низкий
около 1 года назад

Уязвимостей на страницу