/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-2f83-qfpv-cxv2

Published

Last updated

https://images.chainguard.dev/security/CGA-2f83-qfpv-cxv2
Package

tritonserver-backend-vllm-24.04

Repository

Chainguard

Latest Update
Fixed
Fixed Version

24.04-r3

Aliases
  • CVE-2025-24357
  • GHSA-rh4j-5rhw-hr54

Severity

Unknown

Summary

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

Description

Description

The vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It use torch.load function and weights_only parameter is default value False. There is a security warning on https://pytorch.org/docs/stable/generated/torch.load.html, when torch.load load a malicious pickle data it will execute arbitrary code during unpickling.

Impact

This vulnerability can be exploited to execute arbitrary codes and OS commands in the victim machine who fetch the pretrained repo remotely.

Note that most models now use the safetensors format, which is not vulnerable to this issue.

References

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs