CVE-2024-23730
21.01.2024, 17:15
The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.Enginsight
Vendor | Product | Version |
---|---|---|
llamahub | llamahub | 𝑥 < 0.0.67 |
𝑥
= Vulnerable software versions
References