PT-2025-21290 · Unknown+1 · Vita-Mllm Freeze-Omni+1
Ybdesire
·
Published
2025-05-15
·
Updated
2025-05-15
·
CVE-2025-4701
CVSS v2.0
4.3
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
VITA-MLLM Freeze-Omni up to 20250421
Description:
A problematic issue has been found, affecting the
torch.load function in the models/utils.py file. The manipulation of the path argument leads to deserialization, allowing an attack to be launched on the local host.Recommendations:
For VITA-MLLM Freeze-Omni up to 20250421, consider disabling the
torch.load function as a temporary workaround until a patch is available. Restrict access to the models/utils.py file to minimize the risk of exploitation. Avoid using the path argument in the affected function until the issue is resolved.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vita-Mllm Freeze-Omni
Torch