VDB
EN
HIGH 8.8

PYSEC-2025-58

상세

vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It uses the torch.load function and the weights_only parameter defaults to False. When torch.load loads malicious pickle data, it will execute arbitrary code during unpickling. This vulnerability is fixed in v0.7.0.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / vllm
최초 영향 버전: 0 수정 버전: d3d6bb13fb62da3234addf6574922a4ec0513d04
수정 pip install --upgrade 'vllm>=d3d6bb13fb62da3234addf6574922a4ec0513d04'

참고