llama-stack is vulnerable to Remote Code Execution (RCE)
92
Critical Risk
Affected versions of this package are vulnerable to arbitrary code injection because they use eval on untrusted server-supplied data. An attacker who can control the evaluated input can execute arbitrary code in the application's process, leading to full compromise, data exfiltration, or persistent backdoors.
You are affected if you are using a version that falls within the vulnerable range.
llama-stack is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 0.1.5.
Upgrade the llama-stack library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant