Hiyouga LLaMA-Factory 0.9.1

CPE Details

Hiyouga LLaMA-Factory 0.9.1
0.9.1
2025-06-12
16h19 +00:00
2025-06-12
16h19 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:hiyouga:llama-factory:0.9.1:*:*:*:*:*:*:*

Informations

Vendor

hiyouga

Product

llama-factory

Version

0.9.1

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-46567 2025-05-01 17h20 +00:00 LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can exploit this behavior by crafting a malicious `.bin` file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0.
7.8
Haute