📦 Llava

by Hliu

🔍 What is Llava?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-9309

CRITICAL CVSS 9.3 Mar 20, 2025

This SSRF vulnerability in LLaVA's Controller API Server allows attackers to make the server send unauthorized requests to internal or external systems using its credentials. It affects anyone running...

CVE-2024-12068

HIGH CVSS 7.5 Mar 20, 2025

This Server-Side Request Forgery (SSRF) vulnerability in haotian-liu/llava allows attackers to make the server send HTTP requests to arbitrary internal URLs. This could expose sensitive server-side re...

CVE-2024-12065

HIGH CVSS 7.5 Mar 20, 2025

A local file inclusion vulnerability in haotian-liu/llava's Gradio web UI allows attackers to read arbitrary files on the server by sending specially crafted requests. This affects systems running vul...

CVE-2024-9308

MEDIUM CVSS 6.1 Mar 20, 2025

An open redirect vulnerability in haotian-liu/llava v1.2.0 allows attackers to redirect users to malicious websites via crafted URLs. This affects all users of LLaVA-1.6 who access the vulnerable inte...