CVE-2025-45146

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via supplying crafted data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codefuse:modelcache:*:*:*:*:*:*:*:*

History

17 Oct 2025, 18:06

Type Values Removed Values Added
First Time Codefuse modelcache
Codefuse
CPE cpe:2.3:a:codefuse:modelcache:*:*:*:*:*:*:*:*
References () https://github.com/EDMPL/Vulnerability-Research/blob/main/CVE-2025-45146/README.md - () https://github.com/EDMPL/Vulnerability-Research/blob/main/CVE-2025-45146/README.md - Exploit, Third Party Advisory
References () https://github.com/codefuse-ai/ModelCache/blob/e053e0d57b532d4ad9378d2f31bb85a009b77d64/modelcache/manager/data_manager.py#L84C1-L84C43 - () https://github.com/codefuse-ai/ModelCache/blob/e053e0d57b532d4ad9378d2f31bb85a009b77d64/modelcache/manager/data_manager.py#L84C1-L84C43 - Product
References () https://github.com/codefuse-ai/ModelCache/blob/e053e0d57b532d4ad9378d2f31bb85a009b77d64/modelcache/manager/factory.py#L18C1-L18C71 - () https://github.com/codefuse-ai/ModelCache/blob/e053e0d57b532d4ad9378d2f31bb85a009b77d64/modelcache/manager/factory.py#L18C1-L18C71 - Product
References () https://pytorch.org/docs/stable/generated/torch.load.html - () https://pytorch.org/docs/stable/generated/torch.load.html - Technical Description
Summary
  • (es) Se descubrió que ModelCache para LLM hasta la versión v0.2.0 contenía una vulnerabilidad de deserialización a través del componente /manager/data_manager.py. Esta vulnerabilidad permite a los atacantes ejecutar código arbitrario mediante el suministro de datos manipulados.

11 Aug 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-502

11 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-11 16:15

Updated : 2025-10-17 18:06


NVD link : CVE-2025-45146

Mitre link : CVE-2025-45146

CVE.ORG link : CVE-2025-45146


JSON object : View

Products Affected

codefuse

  • modelcache
CWE
CWE-502

Deserialization of Untrusted Data