Sovereignware™ The sovereign AI operating system · archive of record

Ratings / AI App

Llama.cpp

Critical   Rating 1 / 5 · Critical — Active surveillance / serious risk.

Claim evaluated

Llama.cpp, despite its local-first design, poses a significant privacy threat due to numerous critical security vulnerabilities. For instance, in April 2024, a remote code execution (RCE) vulnerability (CVSS 9.6) was found in `llama-cpp-python` due to improper handling of chat te

Analysis

Llama.cpp, despite its local-first design, poses a significant privacy threat due to numerous critical security vulnerabilities. For instance, in April 2024, a remote code execution (RCE) vulnerability (CVSS 9.6) was found in `llama-cpp-python` due to improper handling of chat templates, allowing arbitrary code execution. Furthermore, in April 2026, CVE-2026-34159 identified another critical RCE in the RPC backend, enabling unauthenticated attackers to read and write arbitrary process memory. The project's security policy explicitly warns users under "Data privacy" that "To protect sensitive data from potential leaks or unauthorized access, it is crucial to sandbox the model execution," and advises against using the RPC backend in untrusted environments, acknowledging the inherent risks. These vulnerabilities can lead to unauthorized data access and breaches if not properly mitigated by users.

Sources

Rating Grade Card

The full methodological and legal context for this rating. This card is what we point to when asked to substantiate the claim.

Rating IDark_intel_09414fbb
SubjectLlama.cpp
CategoryAI App
VerdictThreat — red
Beacon stateCritical
Analyzed2026-10-09
CompanyGeorgi Gerganov (creator), no parent company
AnalystSovereign Beacon™ agent — Google Cloud Run · Gemini with Google Search, reads the subject's own privacy policy
ApprovalApproved with the steward's YubiKey (touch) before publication
Data basisPublicly reported information only
Claim framingOpinion based on cited sources, not a statement of intent
Ingest origingcp_beacon_agent
Content fingerprint1ef5295fd75dc64de83c7510ced585bbfa9309fbb120f8e18a2db35681ddcfef
Integrity proofHMAC-SHA256 recorded in the Node 0 attestation ledger (BEACON_RATING_COMMITTED) at commit
Right of replySubmit a response →
Disclaimer. This rating reflects publicly available information as of 2026-10-09. Conditions, policies, ownership, and product behavior may change after publication; re-verify before relying on this rating. The verdict expressed here is an opinion formed from the cited sources and is not a statement of fact about the subject's intent.