Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-55178 1 Meta Platforms Inc 1 Llama Stack 2025-09-25 5.3 Medium
Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.
CVE-2024-50050 1 Meta Platforms Inc 1 Llama Stack 2024-10-24 6.3 Medium
Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.