CVE-2024-34359 is a critical server-side template injection vulnerability in llama-cpp-python, a Python binding for llama.cpp, specifically affecting the `Llama` class when loading .gguf models. The vulnerability arises from the sandbox-less parsing of chat templates within model metadata using `jinja2.Environment`, which can be exploited to achieve remote code execution. With a CVSS score of 9.6 (CRITICAL), this flaw has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring user interaction. While not yet in the KEV catalog, its high EPSS score and active discussion on platforms like Mastodon indicate significant community attention, with a SecurityWeek article highlighting its potential for system and data compromise. There are currently no public Metasploit, Nuclei, or ExploitDB modules available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Abetlen | Llama-Cpp-Python | >= 0.2.30, <= 0.2.71CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.