/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-24357

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-24357

Severity

7.5

High

CVSS V3

Summary

vLLM allows a malicious model RCE by torch.load in hf_model_weights_iterator

Description

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malicious pickle data, it will execute arbitrary code during unpickling. This vulnerability is fixed in v0.7.0.

References

Affected packages


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing