CVE-2025-24357

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malicious pickle data, it will execute arbitrary code during unpickling. This vulnerability is fixed in v0.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*

History

27 Jun 2025, 19:30

Type Values Removed Values Added
First Time Vllm vllm
Vllm
CPE cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
References () https://github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04 - () https://github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04 - Patch
References () https://github.com/vllm-project/vllm/pull/12366 - () https://github.com/vllm-project/vllm/pull/12366 - Issue Tracking, Patch
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54 - () https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54 - Vendor Advisory
References () https://pytorch.org/docs/stable/generated/torch.load.html - () https://pytorch.org/docs/stable/generated/torch.load.html - Technical Description
Summary
  • (es) vLLM es una librería para la inferencia y el servicio de LLM. vllm/model_executor/weight_utils.py implementa hf_model_weights_iterator para cargar el punto de control del modelo, que se descarga desde huggingface. Utiliza la función Torch.load y el parámetro weights_only tiene el valor predeterminado Falso. Cuando Torch.load carga datos pickle maliciosos, ejecutará código arbitrario durante el desensamblaje. Esta vulnerabilidad se corrigió en la versión v0.7.0.

27 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 18:15

Updated : 2025-06-27 19:30


NVD link : CVE-2025-24357

Mitre link : CVE-2025-24357

CVE.ORG link : CVE-2025-24357


JSON object : View

Products Affected

vllm

  • vllm
CWE
CWE-502

Deserialization of Untrusted Data