CVE-2026-18581
ggml-org llama.cpp Jinja Minja Template parser.cpp assertion
CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
| CWE | CWE-617 |
| Vendor | ggml-org |
| Product | llama.cpp |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for ggml-org llama.cpp
Be the first to know when new low vulnerabilities affecting ggml-org llama.cpp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
ggml-org / llama.cpp
e15efe0
References
vuldb.com: https://vuldb.com/vuln/385409 vuldb.com: https://vuldb.com/vuln/385409/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18581 vuldb.com: https://vuldb.com/submit/799118 github.com: https://github.com/ggml-org/llama.cpp/issues/25282 drive.proton.me: https://drive.proton.me/urls/R8D8NGZ6Z0#C2cVZYn5z1Xc github.com: https://github.com/ggml-org/llama.cpp/
Credits
๐ m00dy (VulDB User) VulDB CNA Team