Executive brief
LlamaHub is a library that loads and integrates AI plugins and data connectors. The OpenAPI and ChatGPT plugin loaders use unsafe YAML deserialization, allowing attackers to execute arbitrary code on systems using vulnerable versions. An attacker can craft a malicious YAML configuration file that executes arbitrary commands when processed.
Technical details
The vulnerability stems from use of unsafe YAML deserialization (yaml.load instead of yaml.safe_load) in the OpenAPI and ChatGPT plugin loaders within LlamaHub. This allows arbitrary Python object instantiation and code execution during YAML parsing. Attack requires network access and the ability to provide or intercept a malicious YAML configuration file, but no authentication or user interaction is needed. An attacker can achieve remote code execution in the context of the application. The vulnerability was fixed in version 0.0.67 by switching to safe_load (CWE-502: Deserialization of Untrusted Data).
Affected products
- LlamaIndex llama-hub before 0.0.67
Timeline
- 2024-01-21: disclosed: CVE-2024-23730 and GHSA-297x-2qf3-jrj3 published
- 2024-01-07: patched: Fix merged in PR #841 to use safe_load for YAML
- 2024-01-21: advisory: GitHub Security Advisory GHSA-297x-2qf3-jrj3 issued