Hliu's vulnerability footprint centers on Large Language and Vision Assistant (LLaVA), a widely adopted multimodal AI model that bridges vision and language understanding tasks. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and cluster around web-application and request-handling vulnerabilities including server-side request forgery, resource-exhaustion conditions, cross-site request forgery, path traversal, and open-redirect flaws that are characteristic of networked AI services. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hliu over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9309CRITICAL A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1 | Mar 20, 2025 | 9.3 | 28 | NO | NO |
CVE-2024-10225HIGH A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a | Mar 20, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-12070HIGH A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper han | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-12068HIGH A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perf | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-12065HIGH A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple craft | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-11449HIGH A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized ac | Mar 20, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-9311MEDIUM A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user i | Mar 20, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-9308MEDIUM An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially craf | Mar 20, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hliu.
Media articles that mention a CVE ID that affects a product developed by Hliu — matched by CVE ID, not by vendor name.