VDB
CVE-2025-30405
CVE-2025-30405
PUBLISHED
CVSS 9.800000190734863 CRITICAL
An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 0830af8207240df8d7f35b984cdf8bc35d74fa73.
EPSS 0.60% · 47.2th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.60%
47.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | executorch | 0 |
| Meta Platforms, Inc | ExecuTorch | 0 |
| SwiftURL | executorch | 0 |
| Maven | org.pytorch:executorch-android | 0 |
Timeline
- Aug 7, 2025 CVE Published
- Aug 8, 2025 EPSS Score
- Aug 8, 2025 Coalition ESS Score
- Aug 8, 2025 Coalition ESS Score
- Aug 11, 2025 PoC Published
- Aug 12, 2025 Coalition ESS Score
- Aug 17, 2025 EPSS Score
- Aug 22, 2025 Coalition ESS Score
- Aug 26, 2025 EPSS Score
- Aug 26, 2025 Coalition ESS Score
- Sep 4, 2025 EPSS Score
- Sep 12, 2025 EPSS Score