CRITICAL🇵🇱 Wersja polska

CVE-2024-34359

CVSS 9.6v3.1pub. 2024-05-14upd. 2026-04-15

llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` 's Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.

🤖 AI Analysis
How it works

When loading a .gguf model, the `Llama` class constructor reads the `chat template` field from the file's metadata and passes it to `Jinja2ChatFormatter.to_chat_handler()`, then renders it using a `jinja2.Environment` instance without a configured sandbox. An attacker can embed a specially crafted Jinja2 payload in the metadata of a malicious .gguf file, which will be executed in the Python environment during prompt rendering. As a result, convincing a user to load such a model file results in arbitrary code execution on the server or user's machine.

Impact

An attacker can obtain full arbitrary code execution (RCE) in the context of the process running the library, which may lead to system takeover, data leakage, and further lateral movement in the network.

Mitigation & patch

llama-cpp-python should be updated to a version containing the patch indicated in commit b454f40a9a1787b2b5659cd2cb00819d983185df in accordance with advisory GHSA-56xg-wfcc-g829. Additionally, avoid loading .gguf files from untrusted sources.

Who is affected

The llama-cpp-python library (Python bindings for llama.cpp) — versions indicated in producer references (patch available in commit b454f40a9a1787b2b5659cd2cb00819d983185df).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References