CVE-2024-9308: Hliu Llava
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
Affected products
- Hliu Llava: version 1.2.0 only
Published 2025-03-20. Last modified 2026-06-17.