Skip to content

CVE-2025-24357 Malicious model remote code execution fix bypass with …#1356

Open
i5d6 wants to merge 1 commit intoQwenLM:mainfrom
i5d6:patch-1
Open

CVE-2025-24357 Malicious model remote code execution fix bypass with …#1356
i5d6 wants to merge 1 commit intoQwenLM:mainfrom
i5d6:patch-1

Conversation

@i5d6
Copy link

@i5d6 i5d6 commented May 3, 2025

…PyTorch < 2.6.0

vulnerability where loading a malicious model could result in code execution on the vllm host. The fix applied to specify weights_only=True to calls to torch.load() did not solve the problem prior to PyTorch 2.6.0.

…PyTorch < 2.6.0

vulnerability where loading a malicious model could result in code execution on the vllm host. The fix applied to specify weights_only=True to calls to torch.load() did not solve the problem prior to PyTorch 2.6.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant