Skip to main content

Vendor archive

hiyouga CVEs

Beta · best-effort

5 CVEs tagged to vendor hiyouga1 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-58116

Published Jun 30, 2026

LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-61784

Published Oct 7, 2025

LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated us…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53002

Published Jun 26, 2025

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LL…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46567

Published May 1, 2025

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory proje…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52803

Published Nov 21, 2024

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1