CVE-2024-9308

CVSS 3.0 Score 6.1 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 601

Summary

CVE-2024-9308 is a newly disclosed open redirect vulnerability affecting version v1.2.0 of the haotian-liu/llava library, also known as LLaVA-1.6. This issue enables unauthenticated attackers to manipulate URLs and redirect unsuspecting users to malicious websites. The consequences can be severe, including phishing scams, malware distribution, and potential credential theft. The vulnerability poses a significant risk, particularly in web applications that rely on the affected library for input validation. Users are strongly encouraged to upgrade to a patched version as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share