Transformers Model-Deserialization Remote-Code Execution
The load_repo_checkpoint() function under the TFPreTrainedModel() class. This vulnerability enables attackers to execute arbitrary code and commands by using a carefully crafted serialized payload.
Llama.cpp RPC Heap-overflow Remote-Code Execution
A carefully crafted overflow exploiting Tensor dimension calculations enables arbitrary control over internal memory structures. By partial pointer overwrites, meticulous heap structuring, and Structure-Oriented Programming, bypassed multiple layers of sanitization checks
Llama-Cpp-Python Remote Code Execution by Server-Side Template Injection in Model Metadata
Remote-Code Execution due to Server-Side Template Injection of unportection renderer behaviour in GGUF Model Metadata in Llama-cpp-Python