All 4 CVE vulnerabilities found in LLaMA-Factory, with AI-generated Chinese analysis, references, and POCs.
Vendor: hiyouga
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-61784 | LLaMA Factory's Chat API has Critical SSRF and LFI Vulnerabilities CWE-22 | 7.6 | High | 2025-10-07 |
| CVE-2025-53002 | LLaMA-Factory Remote Code Execution (RCE) Vulnerability CWE-94 | 8.3 | High | 2025-06-26 |
| CVE-2025-46567 | LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py CWE-502 | 6.1 | Medium | 2025-05-01 |
| CVE-2024-52803 | LLama Factory Remote OS Command Injection Vulnerability CWE-79 | 7.5 | High | 2024-11-21 |
All 4 known CVE vulnerabilities affecting LLaMA-Factory with full Chinese analysis, references, and POCs where available.