Tool call execution through user prompt injection (CSRF) of the llama-server Web UI
Published:
The llama-server Web UI of the llama.cpp project is vulnerable to (Reprompt-like user prompt injection vulnerability. An attacker can inject arbitrary user prompt with query parameter (?q=...). This can lead to arbitrary shell command execution, data exfiltration, etc. (through tool calls).