Researchers Uncover Flaws in Python Package for AI Models and PDF.js Used by Firefox
ID: 9c358487-0836-5946-aa44-4cecdef90259
STIX ID: report--9c358487-0836-5946-aa44-4cecdef90259
Feed Name: The Hacker News
Threat Score
Two high-severity vulnerabilities were disclosed: CVE-2024-34359 ("Llama Drama") — a Jinja2 server-side template injection in the llama_cpp_python package that can lead to remote code execution and was fixed in version 0.2.72 — and CVE-2024-4367 — a PDF.js font-handling flaw enabling arbitrary JavaScript execution, patched in Firefox 126 and pdfjs-dist 4.2.67. Both affect widely used software and pose significant supply-chain and client-side risks if left unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
