From thehackernews.com
A critical security flaw has been disclosed in the llama_cpp_python Python package that could be exploited by threat actors to achieve arbitrary code execution.
Tracked as CVE-2024-34359 (CVSS score: 9.7), the flaw has been codenamed Llama Drama by software supply chain security firm Checkmarx.
“If exploited, it could allow attackers to execute arbitrary code on your system, compromising data and operations,” security researcher Guy Nachshon said.
llama_cpp_python, a Python binding for theĀ llama.cpp library, is a popular package with over 3 million downloads to date, allowing developers to integrate AI models with Python.