VDB

CVE-2025-32434

CVE-2025-32434 PUBLISHED

PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.

EPSS 1.94% · 78.2th percentile

Risk Scores

EPSS Score
1.94%
78.2th percentile

Affected Products

VendorProductVersions
Bitnamipytorch0
Bitnamipytorch0

Timeline

  • Jan 21, 1970 Security Advisory
  • Apr 18, 2025 CVE Published
  • Apr 19, 2025 EPSS Score
  • May 1, 2025 EPSS Score
  • May 14, 2025 EPSS Score
  • May 26, 2025 EPSS Score
  • May 28, 2025 Coalition ESS Score
  • Jun 20, 2025 EPSS Score
  • Jul 2, 2025 EPSS Score
  • Jul 14, 2025 EPSS Score
  • Jul 26, 2025 EPSS Score
  • Aug 8, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›