CVE-2024-23730: Llamahub

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.

Affected products

  • Llamahub Llamahub: before 0.0.67 (fixed in 0.0.67)

Published 2024-01-21. Last modified 2026-06-17.