Tag: large language model (LLM) framework

Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks
News

Meta’s Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks

Meta's Llama large language model (LLM) framework has been found to have a high-severity security hole that, if properly exploited, might let an attacker run arbitrary code on the llama-stack inference server. The vulnerability has a CVSS score of 6.3 out of 10.0 and is tagged as CVE-2024-50050. In contrast, Snyk, a supply chain security organization, has given it a critical severity rating of 9.3. According to an investigation published earlier this week by Oligo Security researcher Avi Lumelsky, affected versions of meta-llama are susceptible to deserialization of untrusted data, which allows an attacker to deliver malicious data that has been deserialized and run arbitrary code read more about Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks. Get u...