CVE-2024-9308: Hliu Llava

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

Affected products

  • Hliu Llava: version 1.2.0 only

Published 2025-03-20. Last modified 2026-06-17.