Local LLM
The Model File Is the Payload: GGUF Parser Attack Surface and the Local AI Supply Chain
Four CVEs in the llama.cpp GGUF parser prove a model file is executable code at parse time; a Jinja2 SSTI in Python bindings and a server-side completion-endpoint RCE broaden the surface. What six bugs mean for Ollama, LM Studio, and your homelab intake process.