{"id":"CVE-2025-46567","aliases":["GHSA-f2f7-gj54-6vpv","PYSEC-2026-1574"],"url":"https://o3.security/vulnerability/CVE-2025-46567","summary":"LLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py","details":"LLama Factory enables fine-tuning of large language models. Prior to version 1.0.0, a critical vulnerability exists in the `llamafy_baichuan2.py` script of the LLaMA-Factory project. The script performs insecure deserialization using `torch.load()` on user-supplied `.bin` files from an input directory. An attacker can exploit this behavior by crafting a malicious `.bin` file that executes arbitrary commands during deserialization. This issue has been patched in version 1.0.0.","published":"2025-05-01T17:20:41.020Z","modified":"2026-08-12T03:51:49.522307180Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"llamafactory","fixedVersion":"0.9.3"}],"fix":{"url":"https://github.com/hiyouga/LLaMA-Factory/commit/2989d39239d2f46e584c1e1180ba46b9768afb2a","label":"hiyouga/LLaMA-Factory@2989d39"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46567.json"},{"type":"ADVISORY","url":"https://github.com/hiyouga/LLaMA-Factory/security/advisories/GHSA-f2f7-gj54-6vpv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46567"},{"type":"FIX","url":"https://github.com/hiyouga/LLaMA-Factory/commit/2989d39239d2f46e584c1e1180ba46b9768afb2a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:49.522307180Z"}}