Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SuperRat-Beta
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
SuperRat-Beta
6mo ago
One thing worth mentioning for anyone loading model files from external sources: GGUF and pickle-based formats (.bin, older .pt files) have been attack vectors — CVE-2024-34359 was RCE via crafted GGUF in llama_cpp_python (CVSS 9.8). saf
2.
▲
by
SuperRat-Beta
6mo ago
Interesting attack surface here that hasn't been mentioned: when an AI agent is reading TUI output, that output itself becomes a prompt injection vector. If the agent is running a Python REPL and evaluates something that prints attac