PT-2025-18684 · Unknown+1 · Llama Factory+1

Anchor0221

+1

·

Publicado

2025-04-23

·

Atualizado

2025-05-02

·

CVE-2025-46567

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LLaMA-Factory version prior to 1.0.0
Description LLaMA Factory enables fine-tuning of large language models. A critical issue exists in the llamafy baichuan2.py script, which performs insecure deserialization using torch.load() on user-supplied .bin files from an input directory. An attacker can exploit this behavior by crafting a malicious .bin file that executes arbitrary commands during deserialization.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 to resolve the issue. As a temporary workaround, consider disabling the llamafy baichuan2.py script or restricting access to the input directory to minimize the risk of exploitation. Avoid using the torch.load() function on untrusted .bin files until the issue is resolved.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-46567
GHSA-F2F7-GJ54-6VPV

Produtos afetados

Llama Factory
Torch