The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.
References
Configurations
History
No history.
Information
Published : 2024-01-21 17:15
Updated : 2025-05-30 15:15
NVD link : CVE-2024-23730
Mitre link : CVE-2024-23730
CVE.ORG link : CVE-2024-23730
JSON object : View
Products Affected
llamahub
- llamahub
CWE