Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-58474— whichllm < 0.5.16 Code Injection via run and snippet commands

Quick assessment

Affected
Andyyyy64 whichllm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WhichLLM 0.5.16 之前的版本存在一个代码注入漏洞,影响其 和 命令。如果一个远程攻击者控制着一个 HuggingFace 仓库,他们可以构造一个包含双引号或其他特殊字符的恶意 GGUF 文件名,从而实现任意代码执行。 中的脚本生成功能将来自 HuggingFace 的值(包括来自 Hub API 列表中 字段的 GGUF 变体文件名)直接内插到 Python 源代码中,且未进行转义。这使得攻击者精心构造的文件名能够突破所生成字符串字面量的边界,进而在用户机器上执行注入的代码,且这一过程发生在模型下载开

CVSS 8.8 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Andyyyy64 whichllm < 0.5.16 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-58474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
whichllm < 0.5.16 Code Injection via run and snippet commands
Source: CVE Program / CVE List V5
Vulnerability Description
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant filenames from the Hub API siblings rfilename field, directly into Python source code without escaping, allowing the crafted filename to break out of the generated string literal and execute injected code on the user's machine before any model download occurs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Andyyyy64 whichllm 0 ~ 0.5.16 -

II. Public POCs for CVE-2026-58474

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-58474

登录查看更多情报信息。

Patches & Fixes for CVE-2026-58474 (2)

Vendor Advisories for CVE-2026-58474 (1)

Vendor Pages for CVE-2026-58474 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-58474

No comments yet


Leave a comment