{"id":"CVE-2024-23730","aliases":["GHSA-297x-2qf3-jrj3","PYSEC-2026-393"],"url":"https://o3.security/vulnerability/CVE-2024-23730","summary":"Unsafe yaml deserialization in llama-hub","details":"The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.","published":"2024-01-21T00:00:00Z","modified":"2026-08-12T03:51:36.728314473Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"llama-hub","fixedVersion":"0.0.67"}],"fix":{"url":"https://github.com/run-llama/llama-hub/pull/841/commits/9dc9c21a5c6d0226d1d2101c3121d4f085743d52","label":"run-llama/llama-hub#841"},"references":[{"type":"WEB","url":"https://github.com/run-llama/llama-hub/blob/v0.0.67/CHANGELOG.md"},{"type":"WEB","url":"https://github.com/run-llama/llama-hub/pull/841/commits/9dc9c21a5c6d0226d1d2101c3121d4f085743d52"},{"type":"WEB","url":"https://github.com/run-llama/llama-hub/releases/tag/v0.0.67"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23730.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23730"},{"type":"WEB","url":"https://github.com/run-llama/llama-hub/commit/c01416e737c7747a213a79881b8308c41d043515"},{"type":"PACKAGE","url":"https://github.com/run-llama/llama-hub"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.728314473Z"}}