---
id: CVE-2025-24357
aliases:
  - GHSA-rh4j-5rhw-hr54
  - PYSEC-2025-58
title: 'vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator'
summary: 'vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator'
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: vllm
product: vllm
ecosystem: pip
affected:
  - vllm < 0.7.0
patched:
  - vllm 0.7.0
published: '2025-01-27'
updated: '2026-08-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-rh4j-5rhw-hr54'
references:
  - url: >-
      https://github.com/vllm-project/vllm/security/advisories/GHSA-rh4j-5rhw-hr54
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-24357'
  - url: 'https://github.com/vllm-project/vllm/pull/12366'
  - url: >-
      https://github.com/vllm-project/vllm/commit/d3d6bb13fb62da3234addf6574922a4ec0513d04
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-58.yaml
  - url: 'https://github.com/vllm-project/vllm'
  - url: 'https://github.com/vllm-project/vllm/releases/tag/v0.7.0'
  - url: 'https://pytorch.org/docs/stable/generated/torch.load.html'
tags:
  - osv
  - pip
epss: 0.00697
epssPercentile: 0.51105
ingestedAt: '2026-08-07T19:14:14.691Z'
---

## Overview

### Description
The vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which is downloaded from huggingface. It use torch.load function and weights_only parameter is default value False. There is a security warning on https://pytorch.org/docs/stable/generated/torch.load.html, when torch.load load a malicious pickle data it will execute arbitrary code during unpickling.

### Impact
This vulnerability can be exploited to execute arbitrary codes and OS commands in the victim machine who fetch the pretrained repo remotely.

Note that most models now use the safetensors format, which is not vulnerable to this issue.

### References
* https://pytorch.org/docs/stable/generated/torch.load.html
* Fix: https://github.com/vllm-project/vllm/pull/12366

## Affected packages

- `vllm < 0.7.0`

## Remediation

Upgrade to a patched release:

- `vllm 0.7.0`
