Hiyouga LLaMA-Factory 0.0.9

CPE Details

Hiyouga LLaMA-Factory 0.0.9
0.0.9
2025-06-12
16h19 +00:00
2025-06-12
16h19 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:hiyouga:llama-factory:0.0.9:*:*:*:*:*:*:*

Informations

Vendor

hiyouga

Product

llama-factory

Version

0.0.9

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-46567 2025-05-01 17h20 +00:00 LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can exploit this behavior by crafting a malicious `.bin` file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0.
7.8
High