Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hiyouga

First CVE: Nov 21, 2024Active for: 2 yearsTotal CVEs: 5

Hiyouga maintains a focused machine-learning framework product, LLaMA-Factory, which facilitates fine-tuning and deployment of large language models. The vulnerability pattern observed in this product centers on input-handling and code-execution weaknesses—including deserialization flaws, code injection, path traversal, cross-site scripting, and OS command injection—reflecting the complexity of model serving and dynamic code generation inherent to training and inference pipelines. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.9
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hiyouga over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 21, 2024
20 months ago
Most Recent CVE
Jun 30, 2026
27 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-58116HIGH
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model p
Jun 30, 20268.838NONO
CVE-2025-61784HIGH
LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated use
Oct 7, 20258.127NONO
CVE-2025-53002CRITICAL
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLa
Jun 26, 20259.827NONO
CVE-2024-52803CRITICAL
LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vul
Nov 21, 20249.826NONO
CVE-2025-46567HIGH
LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory projec
May 1, 20257.822NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
60%
40%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hiyouga.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hiyouga — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hiyouga's Products

View all 2 CNAs →

Top CWEs