Versions of whichllm before 0.5.16 allow arbitrary Python code execution through the run and snippet commands when users select a malicious Hugging Face model repository. The CLI inserted unescaped Hugging Face Hub siblings[].rfilename metadata—including GGUF filenames and model IDs—directly into generated Python scripts, enabling an attacker-controlled filename containing quotes or special characters to terminate a string literal and inject statements before the requested model downloads.
The project fixed the flaw in commit 77e8dc9 (PR #147), released in v0.5.16, by rendering generated metadata with Python representations (!r) rather than placing values in quoted literals. Organizations using whichllm should upgrade to 0.5.16 or later and treat untrusted model repositories and metadata as potentially malicious until updated.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
whichllm commit 77e8dc9 fixed unsafe interpolation of model metadata and GGUF filenames in scripts generated by the `run` and `snippet` commands. The fix uses Python literal representations (`!r`) and adds tests confirming crafted filenames remain data rather than executable code; it is included in v0.5.16.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.