PT-2025-47378 · Unknown · Modular Max Serve

Published

2025-11-18

·

Updated

2026-04-08

·

CVE-2025-60455

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Modular Max Serve versions prior to 25.6
Description An unsafe deserialization issue exists in Modular Max Serve when the "--experimental-enable-kvcache-agent" feature is utilized. This allows attackers to potentially execute arbitrary code. The issue occurs due to improper handling of deserialized data.
Recommendations Update Modular Max Serve to version 25.6 or later. Disable the "--experimental-enable-kvcache-agent" feature.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-60455
GHSA-7XCV-9J6C-2FMC

Affected Products

Modular Max Serve