The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-01-21T00:00:00

Updated: 2024-08-01T23:13:07.298Z

Reserved: 2024-01-21T00:00:00

Link: CVE-2024-23730

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-21T17:15:44.373

Modified: 2024-01-29T15:22:56.753

Link: CVE-2024-23730

cve-icon Redhat

No data.