Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12156 | LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can exploit this behavior by crafting a malicious `.bin` file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0. |
Github GHSA |
GHSA-f2f7-gj54-6vpv | LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py |
Tue, 17 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hiyouga
Hiyouga llama-factory |
|
| CPEs | cpe:2.3:a:hiyouga:llama-factory:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hiyouga
Hiyouga llama-factory |
Fri, 02 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 May 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can exploit this behavior by crafting a malicious `.bin` file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0. | |
| Title | LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-02T17:29:45.664Z
Reserved: 2025-04-24T21:10:48.175Z
Link: CVE-2025-46567
Updated: 2025-05-02T17:29:37.760Z
Status : Analyzed
Published: 2025-05-01T18:15:58.117
Modified: 2025-06-17T14:19:39.290
Link: CVE-2025-46567
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA