VYPR
Vendor

Hiyouga

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2025-53002HigJun 26, 2025
    risk 0.47cvss 8.3epss 0.01

    LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without…

  • CVE-2025-61784HigOct 7, 2025
    risk 0.42cvss 7.6epss 0.00

    LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the server to make arbitrary HTTP requests to internal and external networks. This can…

  • CVE-2024-52803HigNov 21, 2024
    risk 0.42cvss 7.5epss 0.02

    LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute…

  • CVE-2025-46567MedMay 1, 2025
    risk 0.33cvss 6.1epss 0.00

    LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files…

  • CVE-2026-58116CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input…