Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Local File Inclusion in haotian-liu/llava
Vulnerability Description
A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
LLaVA 输入验证错误漏洞
Vulnerability Description
LLaVA是Haotian Liu个人开发者的一个应用程序。 LLaVA存在输入验证错误漏洞,该漏洞源于gradio web UI组件输入验证不当,可能导致本地文件包含攻击。
CVSS Information
N/A
Vulnerability Type
N/A