---
id: CVE-2026-18581
title: A vulnerability was determined in ggml-org llama.cpp e15efe0
summary: >-
  A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this
  issue is some unknown functionality of the file common/jinja/parser.cpp of the
  component Jinja Minja Template Parser. Executing a manipulation with the input
  …
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-617
published: '2026-08-03'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18581'
references:
  - url: 'https://drive.proton.me/urls/R8D8NGZ6Z0#C2cVZYn5z1Xc'
    label: cna@vuldb.com
  - url: 'https://github.com/ggml-org/llama.cpp/'
    label: cna@vuldb.com
  - url: 'https://github.com/ggml-org/llama.cpp/issues/25282'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-18581'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/799118'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/385409'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/385409/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-03T01:21:07.667Z'
epss: 0.0016
epssPercentile: 0.04361
---

## Overview

A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
