-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability arises because the fix applied in vLLM (adding weights_only=True to torch.load calls) is ineffective for versions of PyTorch prior to 2.6.0, as stated in CVE-2025-24357 and the related PyTorch advisory GHSA-53q9-r3pm-6pq6. The commit 8dae1e337b4377b650a03ce020774cc9c48d25a2 (from PR #12366, which fixed the original GHSA-rh4j-5rhw-hr54) shows all the locations where torch.load was modified. These locations remain vulnerable if vLLM is used with an unpatched PyTorch version. The functions listed are those that directly invoke torch.load on potentially untrusted model files or weights, making them the points where malicious code execution could be triggered.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| vllm | pip | < 0.8.0 | 0.8.0 |
Ongoing coverage of React2Shell