CVE-2026-52131

HIGH CVSS 3.1: 7.5 EPSS 0.26%
Updated Sep 04, 2026
Ggml
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before b5693
Type CWE-617
Vendor Ggml
Public PoC No

llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Ggml Llama.Cpp
cpe:2.3:a:ggml:llama.cpp:*:*:*:*:*:*:*:*
<= b5693