VDB
CVE-2025-3000
CVE-2025-3000
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
EPSS 0.20% · 8.7th percentile
Risk Scores
CVSS 4.0
4.800000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
0.20%
8.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | pytorch | 2.6.0 |
| Bitnami | pytorch | 2.6.0 |
Timeline
- Mar 31, 2025 CVE Published
- Mar 31, 2025 Coalition ESS Score
- Apr 1, 2025 EPSS Score
- Apr 1, 2025 Coalition ESS Score
- Apr 7, 2025 Coalition ESS Score
- Apr 12, 2025 Coalition ESS Score
- Apr 14, 2025 EPSS Score
- Apr 27, 2025 EPSS Score
- May 11, 2025 EPSS Score
- May 24, 2025 EPSS Score
- May 27, 2025 Coalition ESS Score
- Jun 5, 2025 Coalition ESS Score