icon

We found results for “

CVE-2025-46567

Good to know:

icon

Date: May 1, 2025

LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the "llamafy_baichuan2.py" script of the LLaMA-Factory project. The script performs insecure deserialization using "torch.load()" on user-supplied ".bin" files from an input directory. An attacker can exploit this behavior by crafting a malicious ".bin" file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0.

Severity Score

Severity Score

Weakness Type (CWE)

Deserialization of Untrusted Data

CWE-502

Top Fix

icon

Upgrade Version

Upgrade to version llamafactory - 0.9.3

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us