{"id":"GHSA-m9mp-6x32-5rhg","aliases":[],"url":"https://o3.security/vulnerability/GHSA-m9mp-6x32-5rhg","summary":"scio is vunerable to  Remote Command Execution  through PyTorch","details":"### Impact\nPyTorch reported a [**critical** vulnerability](https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6) when using `torch.load`, even with option `weights_only=True`, for `torch <= 2.5.1`.\n\nIn `scio <= 1.0.0`, the lower bound for `torch` is `2.3`.\n\n### Patches\nThe lower bound was changed to `torch >= 2.6`, starting from `scio >= 1.0.1` (currently in dev state).\n\n### Workarounds\nYou can manually check that you are using `torch >= 2.6`.","published":"2025-10-09T14:22:00Z","modified":"2025-10-09T14:50:16.086190Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"scio-pypi","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ThalesGroup/scio/security/advisories/GHSA-m9mp-6x32-5rhg"},{"type":"WEB","url":"https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6"},{"type":"PACKAGE","url":"https://github.com/ThalesGroup/scio"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-09T14:50:16.086190Z"}}