Hiyouga maintains a focused machine-learning framework product, LLaMA-Factory, which facilitates fine-tuning and deployment of large language models. The vulnerability pattern observed in this product centers on input-handling and code-execution weaknesses—including deserialization flaws, code injection, path traversal, cross-site scripting, and OS command injection—reflecting the complexity of model serving and dynamic code generation inherent to training and inference pipelines. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hiyouga over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58116HIGH LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model p | Jun 30, 2026 | 8.8 | 38 | NO | NO |
CVE-2025-61784HIGH LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated use | Oct 7, 2025 | 8.1 | 27 | NO | NO |
CVE-2025-53002CRITICAL LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLa | Jun 26, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-52803CRITICAL LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vul | Nov 21, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-46567HIGH LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory projec | May 1, 2025 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hiyouga.
Media articles that mention a CVE ID that affects a product developed by Hiyouga — matched by CVE ID, not by vendor name.