Code Injection Vulnerability in whichllm by Andyyyy64
CVE-2026-58474
8.6HIGH
What is CVE-2026-58474?
A critical code injection vulnerability exists in whichllm versions prior to 0.5.16. This flaw allows remote attackers controlling a HuggingFace repository to execute arbitrary code locally. By crafting a malicious GGUF file name containing double quotes or other special characters, attackers can manipulate the script generation function in cli.py. This function directly integrates HuggingFace-derived values, exposing users to risks of executing malicious code injected during the model download process. Immediate action is recommended to upgrade to the latest version to mitigate these risks.
Affected Version(s)
whichllm 0
