Impact
A use‑after‑free in the common_chat_peg_mapper::map function of llama.cpp allows an attacker who can send a crafted POST /completion request to the llama‑server to corrupt heap memory via a dangling current_tool pointer. By emitting a tool‑id after a tool‑close tag in the chat_parser payload, the attacker can trigger a heap write primitive that may lead to arbitrary code execution or a denial‑of‑service crash.
Affected Systems
Any installation of ggml‑org’s llama.cpp that predates commit b11393 is vulnerable. The flaw resides in the code path exercised by the server’s chat parsing logic and does not affect later releases that incorporate the fix.
Risk and Exploitability
The CVSS score of 9.2 indicates a high severity vulnerability. Although an EPSS score is not available and the issue is not listed in the CISA KEV catalog, the vulnerability is exploitable over an unauthenticated remote connection that can transmit a malicious payload to the server. Successful exploitation could compromise confidentiality, integrity, or availability of the affected system.
OpenCVE Enrichment