vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses...
Full analysis pending. Showing NVD description excerpt.
Affected Systems
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| vllm | pip | < 0.7.0 | 0.7.0 |
| vllm | pip | — | No patch |
Severity & Risk
Recommended Action
Patch available
Update vllm to version 0.7.0
Compliance Impact
Compliance analysis pending. Sign in for full compliance mapping when available.
Technical Details
NVD Description
vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malicious pickle data, it will execute arbitrary code during unpickling. This vulnerability is fixed in v0.7.0.
Weaknesses (CWE)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References
- github.com/advisories/GHSA-rh4j-5rhw-hr54
- github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-58.yaml
- github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04
- github.com/vllm-project/vllm/pull/12366
- github.com/vllm-project/vllm/releases/tag/v0.7.0
- github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54
- nvd.nist.gov/vuln/detail/CVE-2025-24357
- pytorch.org/docs/stable/generated/torch.load.html
- github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04 Patch
- github.com/vllm-project/vllm/pull/12366 Issue Patch
- github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54 Vendor
- pytorch.org/docs/stable/generated/torch.load.html Technical