<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:43:32 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-5469</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5469</link>
      <description>EUVD-2026-5469</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5469</guid>
    </item>
    <item>
      <title>fkie_cve-2024-34359</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-34359</link>
      <description>&lt;p&gt;llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` &amp;#39;s Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` &amp;#39;s Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-34359</guid>
    </item>
    <item>
      <title>GHSA-56xg-wfcc-g829 — llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-56xg-wfcc-g829</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: llama-cpp-python&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` &amp;#39;s Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to RCE by a carefully constructed payload.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink&lt;/p&gt;
&lt;p&gt;### `llama.py` -&amp;gt; `class Llama` -&amp;gt; `__init__`:&lt;/p&gt;
&lt;p&gt;```python
class Llama:
    &amp;#34;&amp;#34;&amp;#34;High-level Python wrapper for a llama.cpp model.&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;__backend_initialized = False&lt;/p&gt;
&lt;p&gt;def __init__(
        self,
        model_path: str,
		# lots of params; Ignoring
    ):
 
        self.verbose = verbose&lt;/p&gt;
&lt;p&gt;set_verbose(verbose)&lt;/p&gt;
&lt;p&gt;if not Llama.__backend_initialized:
            with suppress_stdout_stderr(disable=verbose):
                llama_cpp.llama_backend_init()
            Llama.__backend_initialized = True&lt;/p&gt;
&lt;p&gt;# Ignoring lines of unrelated codes.....&lt;/p&gt;
&lt;p&gt;try:
            self.metadata = self…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: llama-cpp-python&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` &amp;#39;s Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to RCE by a carefully constructed payload.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink&lt;/p&gt;
&lt;p&gt;### `llama.py` -&amp;gt; `class Llama` -&amp;gt; `__init__`:&lt;/p&gt;
&lt;p&gt;```python
class Llama:
    &amp;#34;&amp;#34;&amp;#34;High-level Python wrapper for a llama.cpp model.&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;__backend_initialized = False&lt;/p&gt;
&lt;p&gt;def __init__(
        self,
        model_path: str,
		# lots of params; Ignoring
    ):
 
        self.verbose = verbose&lt;/p&gt;
&lt;p&gt;set_verbose(verbose)&lt;/p&gt;
&lt;p&gt;if not Llama.__backend_initialized:
            with suppress_stdout_stderr(disable=verbose):
                llama_cpp.llama_backend_init()
            Llama.__backend_initialized = True&lt;/p&gt;
&lt;p&gt;# Ignoring lines of unrelated codes.....&lt;/p&gt;
&lt;p&gt;try:
            self.metadata = self…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-56xg-wfcc-g829</guid>
    </item>
    <item>
      <title>PYSEC-2026-392 — llama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-392</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: llama-cpp-python&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` &amp;#39;s Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to RCE by a carefully constructed payload.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink&lt;/p&gt;
&lt;p&gt;### `llama.py` -&amp;gt; `class Llama` -&amp;gt; `__init__`:&lt;/p&gt;
&lt;p&gt;```python
class Llama:
    &amp;#34;&amp;#34;&amp;#34;High-level Python wrapper for a llama.cpp model.&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;__backend_initialized = False&lt;/p&gt;
&lt;p&gt;def __init__(
        self,
        model_path: str,
		# lots of params; Ignoring
    ):
 
        self.verbose = verbose&lt;/p&gt;
&lt;p&gt;set_verbose(verbose)&lt;/p&gt;
&lt;p&gt;if not Llama.__backend_initialized:
            with suppress_stdout_stderr(disable=verbose):
                llama_cpp.llama_backend_init()
            Llama.__backend_initialized = True&lt;/p&gt;
&lt;p&gt;# Ignoring lines of unrelated codes.....&lt;/p&gt;
&lt;p&gt;try:
            self.metadata = self…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: llama-cpp-python&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;`llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` &amp;#39;s Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to RCE by a carefully constructed payload.&lt;/p&gt;
&lt;p&gt;## Source-to-Sink&lt;/p&gt;
&lt;p&gt;### `llama.py` -&amp;gt; `class Llama` -&amp;gt; `__init__`:&lt;/p&gt;
&lt;p&gt;```python
class Llama:
    &amp;#34;&amp;#34;&amp;#34;High-level Python wrapper for a llama.cpp model.&amp;#34;&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;__backend_initialized = False&lt;/p&gt;
&lt;p&gt;def __init__(
        self,
        model_path: str,
		# lots of params; Ignoring
    ):
 
        self.verbose = verbose&lt;/p&gt;
&lt;p&gt;set_verbose(verbose)&lt;/p&gt;
&lt;p&gt;if not Llama.__backend_initialized:
            with suppress_stdout_stderr(disable=verbose):
                llama_cpp.llama_backend_init()
            Llama.__backend_initialized = True&lt;/p&gt;
&lt;p&gt;# Ignoring lines of unrelated codes.....&lt;/p&gt;
&lt;p&gt;try:
            self.metadata = self…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-392</guid>
    </item>
  </channel>
</rss>
