ID:12626 - Exploit for Deserialization of Untrusted Data in PyTorch - CVE-2025-32434

 
Main Vulnerability Database Exploits ID:12626 - Exploit for Deserialization of Untrusted Data in PyTorch - CVE-2025-32434

ID:12626 - Exploit for Deserialization of Untrusted Data in PyTorch - CVE-2025-32434

Published: April 23, 2026


Vulnerability identifier: #VU109603
Vulnerability risk: High
CVE-ID: CVE-2025-32434
CWE-ID: CWE-502
Exploitation vector: Remote access
Vulnerable software:
PyTorch

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data when loading a model using torch.load with weights_only=True. A remote attacker can trick the victim into loading a specially crafted model and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.