A critical vulnerability discovered recently in a Python package used by AI application developers can allow arbitrary code execution, putting systems and data at risk.
The issue, discovered by researcher Patrick Peng, is tracked as CVE-2024-34359 and it has been dubbed Llama Drama.
Cybersecurity firm Checkpoint on Thursday published a blog post describing the vulnerability and its impact.
CVE-2024-34359 is related to the Jinja2 template rendering Python tool, which is mainly used for generating HTML, and the llama cpp python package, which is used for integrating AI models with Python.
Llama cpp python uses Jinja2 for processing model metadata, but failed to use certain safeguards, enabling template injection attacks.
According to the security firm, the vulnerability can be exploited for arbitrary code execution on systems that use the affected Python package.
The company found that more than 6,000 AI models on the Hugging Face AI community that use llama cpp python and Jinja2 are impacted.
The vulnerability has been patched with the release of llama cpp python 0.2.72.
This Cyber News was published on packetstormsecurity.com. Publication date: Sat, 18 May 2024 08:43:05 +0000