Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.
References
| Link | Resource |
|---|---|
| http://oneflow.com | Product |
| https://github.com/Daisy2ang | Not Applicable |
| https://github.com/Oneflow-Inc/oneflow | Product |
| https://github.com/Oneflow-Inc/oneflow/issues/10666 | Exploit Issue Tracking Patch |
Configurations
History
31 Dec 2025, 18:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Oneflow oneflow
Oneflow |
|
| CPE | cpe:2.3:a:oneflow:oneflow:0.9.0:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () http://oneflow.com - Product | |
| References | () https://github.com/Daisy2ang - Not Applicable | |
| References | () https://github.com/Oneflow-Inc/oneflow - Product | |
| References | () https://github.com/Oneflow-Inc/oneflow/issues/10666 - Exploit, Issue Tracking, Patch |
12 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-20 |
10 Nov 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-10 22:15
Updated : 2025-12-31 18:26
NVD link : CVE-2025-63397
Mitre link : CVE-2025-63397
CVE.ORG link : CVE-2025-63397
JSON object : View
Products Affected
oneflow
- oneflow
CWE
CWE-20
Improper Input Validation
