llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` 's Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.
When loading a .gguf model, the `Llama` class constructor reads the `chat template` field from the file's metadata and passes it to `Jinja2ChatFormatter.to_chat_handler()`, then renders it using a `jinja2.Environment` instance without a configured sandbox. An attacker can embed a specially crafted Jinja2 payload in the metadata of a malicious .gguf file, which will be executed in the Python environment during prompt rendering. As a result, convincing a user to load such a model file results in arbitrary code execution on the server or user's machine.
An attacker can obtain full arbitrary code execution (RCE) in the context of the process running the library, which may lead to system takeover, data leakage, and further lateral movement in the network.
llama-cpp-python should be updated to a version containing the patch indicated in commit b454f40a9a1787b2b5659cd2cb00819d983185df in accordance with advisory GHSA-56xg-wfcc-g829. Additionally, avoid loading .gguf files from untrusted sources.
The llama-cpp-python library (Python bindings for llama.cpp) — versions indicated in producer references (patch available in commit b454f40a9a1787b2b5659cd2cb00819d983185df).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H