pypi package report

Is llamafactory safe?

4 known vulnerabilities, worst severity HIGH.

cvss
7.6

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-527m-2xhr-j27g, the advisory selected below

// advisories

GHSA-527m-2xhr-j27g

HIGHCVE-2025-61784

A Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the server to make arbitrary HTTP requests to internal and external networks. This can lead to the exposure of sensitive internal services, reconnaissance of the internal network, or interaction with third-party services. The same mechanism also allows for a Local File Inclusion (LFI) vulnerab

Affected
<= 0.9.3
Fixed in
0.9.4
Weakness
CWE-22
Published
2025-10-07
Source
github

GHSANVDMITREreferencereference


// dependencies

31 direct, 13 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

12 published models

0 declared · 12 observed · 0 inferred

ModelEvidence
tencent/Hy3observed
tencent/Hy3-FP8observed

Sign in to see all 10 models and per-model risk

12 published AI models are associated with this package: 0 name it in a requirements or pyproject file, 12 load it or import it directly, and 0 are inferred from the runtime stack their declared library pulls in. Only 0 state a version requirement, so this is not a count of affected models.


Checked 2026-09-22 at 02:38 UTC. The most recent advisory here was published 2025-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is llamafactory safe? pypi package security report | CyberXYZ