Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16239 | FunAudioLLM InspireMusic deserialization vulnerability |
Github GHSA |
GHSA-pgp9-g5q8-j3wp | FunAudioLLM InspireMusic deserialization vulnerability |
Wed, 28 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 25 May 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py of the component Pickle Data Handler. The manipulation leads to deserialization. An attack has to be approached locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is 784cbf8dde2cf1456ff808aeba23177e1810e7a9. It is recommended to apply a patch to fix this issue. | |
| Title | FunAudioLLM InspireMusic Pickle Data model.py load_state_dict deserialization | |
| Weaknesses | CWE-20 CWE-502 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-05-28T17:38:41.538Z
Reserved: 2025-05-24T16:25:39.206Z
Link: CVE-2025-5148
Updated: 2025-05-27T14:21:40.273Z
Status : Deferred
Published: 2025-05-25T12:15:20.417
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5148
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA