cbcvebase.
CVE-2025-3000
published 2025-03-31

CVE-2025-3000: A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory…

PriorityP427medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.18%
8.1th percentile
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Affected

8 ranges
VendorProductVersion rangeFixed in
better-authbetter-auth>= 0 < 1.2.101.2.10
debianpytorch
github.comgogs_gogs>= 0 < 0.13.3-0.20250608224432-110117b2e5e50.13.3-0.20250608224432-110117b2e5e5
gogs.iogogs>= 0 < 0.13.3-0.20250608224432-110117b2e5e50.13.3-0.20250608224432-110117b2e5e5
googlechrome_chrome
linuxfoundationpytorch
nuxtrspack-builder>= 3.12.2 < 3.15.33.15.3
nuxtwebpack-builder>= 3.0.0 < 3.15.33.15.3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
ghsa8.8HIGH
osv4.8MEDIUM
vendor_cisco7.4HIGH
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.