Miggo Logo

CVE-2025-24357: vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.24274%
Published
1/27/2025
Updated
1/27/2025
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
vllmpip< 0.7.00.7.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### **s*ription T** vllm/mo**l_*x**utor/w*i**t_utils.py impl*m*nts **_mo**l_w*i**ts_it*r*tor to lo** t** mo**l ****kpoint, w*i** is *ownlo**** *rom *u**in*****. It us* tor**.lo** *un*tion *n* w*i**ts_only p*r*m*t*r is ****ult v*lu* **ls*. T**r* is *

Reasoning

No *n*lysis *v*il**l*