Product
Security Bypass Vulnerability in LiteLLM
3 TTPs 1 CVEA vulnerability in LiteLLM, tracked as CVE-2024-4786, allows remote authenticated attackers to circumvent established security controls.
Detection of Local LLM Model File Creation on Endpoints
2 rules 5 TTPsThis brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.
LangSmith SDK Untrusted Manifest Deserialization Vulnerability
2 rules 3 TTPsThe LangSmith SDK is vulnerable to untrusted manifest deserialization when pulling public prompts via `pull_prompt`, potentially leading to SSRF, prompt injection, or sensitive data exposure; CVE-2026-45134.