A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component. | |
Title | Local File Inclusion in haotian-liu/llava | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:09:49.632Z
Updated: 2025-03-20T18:34:08.088Z
Reserved: 2024-12-02T21:16:10.059Z
Link: CVE-2024-12065

Updated: 2025-03-20T17:52:59.642Z

Status : Received
Published: 2025-03-20T10:15:26.887
Modified: 2025-03-20T10:15:26.887
Link: CVE-2024-12065

No data.