---
id: CVE-2025-3001
aliases:
  - PYSEC-2025-195
  - BIT-pytorch-2025-3001
  - GHSA-qfhq-4f3w-5fph
title: >-
  A vulnerability classified as critical was found in PyTorch 2.6.0. This
  vulnerability affects the function torch.lstm_cell. The manipulat…
summary: >-
  A vulnerability classified as critical was found in PyTorch 2.6.0. This
  vulnerability affects the function torch.lstm_cell. The manipulation leads to
  memory corruption. The attack needs to be approached locally. The exploit has
  been disc…
severity: none
vendor: torch
product: torch
ecosystem: pip
affected:
  - torch <= 2.6.0-NA
published: '2025-03-31'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2025-195'
references:
  - url: 'https://vuldb.com/?id.302050'
  - url: 'https://vuldb.com/?submit.524212'
  - url: 'https://github.com/pytorch/pytorch/issues/149626'
  - url: 'https://github.com/pytorch/pytorch/issues/149626#issue-2935860995'
  - url: 'https://vuldb.com/?ctiid.302050'
  - url: 'https://github.com/advisories/GHSA-qfhq-4f3w-5fph'
tags:
  - osv
  - pip
epss: 0.00198
epssPercentile: 0.08573
ingestedAt: '2026-07-13T18:58:06.535Z'
---

## Overview

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

## Affected packages

- `torch <= 2.6.0-NA`

## Remediation

Refer to the advisory for the patched release.
