cbcvebase.
CVE-2025-24357
published 2025-01-27

CVE-2025-24357: vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which…

PriorityP349high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.69%
48.3th percentile
vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malicious pickle data, it will execute arbitrary code during unpickling. This vulnerability is fixed in v0.7.0.

Affected

5 ranges
VendorProductVersion rangeFixed in
vllm-projectvllm< 0.7.00.7.0
vllmvllm< 0.7.00.7.0
vllmvllm>= 0 < d3d6bb13fb62da3234addf6574922a4ec0513d04d3d6bb13fb62da3234addf6574922a4ec0513d04
vllmvllm>= 0 < 0.7.00.7.0
vllmvllm>= 0 < 0.8.00.8.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.