The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Llamahub |
Llamahub |
* |
0.0.67 (excluding) |
References