LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute arbitrary OS commands on the host system. The issue is caused by insecure usage of the `Popen` function with `shell=True`, coupled with unsanitized user input. Immediate remediation is required to mitigate the risk. This vulnerability is fixed in 0.9.1.
History

Thu, 21 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Llama-factory
Llama-factory llama-factory
CPEs cpe:2.3:a:llama-factory:llama-factory:*:*:*:*:*:*:*:*
Vendors & Products Llama-factory
Llama-factory llama-factory
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 17:00:00 +0000

Type Values Removed Values Added
Description LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute arbitrary OS commands on the host system. The issue is caused by insecure usage of the `Popen` function with `shell=True`, coupled with unsanitized user input. Immediate remediation is required to mitigate the risk. This vulnerability is fixed in 0.9.1.
Title LLama Factory Remote OS Command Injection Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-21T16:53:18.398Z

Updated: 2024-11-21T21:12:06.172Z

Reserved: 2024-11-15T17:11:13.441Z

Link: CVE-2024-52803

cve-icon Vulnrichment

Updated: 2024-11-21T21:11:55.323Z

cve-icon NVD

Status : Received

Published: 2024-11-21T17:15:24.470

Modified: 2024-11-21T17:15:24.470

Link: CVE-2024-52803

cve-icon Redhat

No data.