CVE-2025-24357

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malicious pickle data, it will execute arbitrary code during unpickling. This vulnerability is fixed in v0.7.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*

History

27 Jun 2025, 19:30

Type Values Removed Values Added
Summary
  • (es) vLLM es una librería para la inferencia y el servicio de LLM. vllm/model_executor/weight_utils.py implementa hf_model_weights_iterator para cargar el punto de control del modelo, que se descarga desde huggingface. Utiliza la función Torch.load y el parámetro weights_only tiene el valor predeterminado Falso. Cuando Torch.load carga datos pickle maliciosos, ejecutará código arbitrario durante el desensamblaje. Esta vulnerabilidad se corrigió en la versión v0.7.0.
First Time Vllm vllm
Vllm
CPE cpe:2.3:a:vllm:vllm:*:*:*:*:*:*:*:*
References () https://github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04 - () https://github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04 - Patch
References () https://github.com/vllm-project/vllm/pull/12366 - () https://github.com/vllm-project/vllm/pull/12366 - Issue Tracking, Patch
References () https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54 - () https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54 - Vendor Advisory
References () https://pytorch.org/docs/stable/generated/torch.load.html - () https://pytorch.org/docs/stable/generated/torch.load.html - Technical Description

27 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 18:15

Updated : 2025-06-27 19:30


NVD link : CVE-2025-24357

Mitre link : CVE-2025-24357

CVE.ORG link : CVE-2025-24357


JSON object : View

Products Affected

vllm

  • vllm
CWE
CWE-502

Deserialization of Untrusted Data