Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-34359

47
FAUCET Score

CVE-2024-34359 is a critical server-side template injection vulnerability in llama-cpp-python, a Python binding for llama.cpp, specifically affecting the `Llama` class when loading .gguf models. The vulnerability arises from the sandbox-less parsing of chat templates within model metadata using `jinja2.Environment`, which can be exploited to achieve remote code execution. With a CVSS score of 9.6 (CRITICAL), this flaw has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring user interaction. While not yet in the KEV catalog, its high EPSS score and active discussion on platforms like Mastodon indicate significant community attention, with a SecurityWeek article highlighting its potential for system and data compromise. There are currently no public Metasploit, Nuclei, or ExploitDB modules available.

Impacted Technologies

VendorProductVersion(s)CPE
AbetlenLlama-Cpp-Python
>= 0.2.30, <= 0.2.71CNA affected

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
28.42%
Probability of exploitation in next 30 days
EPSS Percentile
97.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.2842 is in the 98th percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: llama-cpp-pythonFixed in: 0.2.72

Vendor Advisories (1)

pipGHSA-56xg-wfcc-g829critical

llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata

May 13, 2024

References

github.com / abetlen/llama-cpp-python/commit/b454f40a9a1787b2b5659cd2cb00819d983185df
github.com / abetlen/llama-cpp-python/security/advisories/GHSA-56xg-wfcc-g829