Improper Initialization in PyTorch - CVE-2025-2149
Published: March 17, 2026
Vulnerability identifier: #VU124048
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2149
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists in the function nnq_Sigmoid of the component Quantized Sigmoid Module. A local user can run a specially crafted application to execute arbitrary code with escalated privileges on the system.
Affected software
PyTorch
Knowledge Catalog Premium Cartridge
IBM Watson Knowledge Catalog in Cloud Pak for Data
Knowledge Catalog Premium Cartridge
IBM Watson Knowledge Catalog in Cloud Pak for Data
How to mitigate CVE-2025-2149
Install updates from vendor's website.
PyTorch - update to 2.7.0
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2