WhichLLM 0.5.16 之前的版本存在一个代码注入漏洞,影响其 和 命令。如果一个远程攻击者控制着一个 HuggingFace 仓库,他们可以构造一个包含双引号或其他特殊字符的恶意 GGUF 文件名,从而实现任意代码执行。 中的脚本生成功能将来自 HuggingFace 的值(包括来自 Hub API 列表中 字段的 GGUF 变体文件名)直接内插到 Python 源代码中,且未进行转义。这使得攻击者精心构造的文件名能够突破所生成字符串字面量的边界,进而在用户机器上执行注入的代码,且这一过程发生在模型下载开
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet