CVE-2025-32434·Python vulnerability
PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.
- Severity
- critical
- Software
- Python
- Fixed in
- 2.6.0
- Published
- 2025-04-18
Affected versions
Until: 2.6.0
Fixed in: 2.6.0
How to fix this CVE
Upgrade PyTorch to version 2.6.0 or later to resolve a critical remote code execution flaw that bypasses the weights_only=True safety mechanism in torch.load(). Organizations should prioritize this update immediately as the vulnerability allows arbitrary command execution during model deserialization. After updating, verify the patch by checking the PyTorch version and testing model loading operations with weights_only=True enabled.
sudo dnf install --refresh python3-torch-2.6.0 || sudo pip install --upgrade torch>=2.6.0Defensia detects this vulnerability
How to check if you are affected
- Check the installed PyTorch version: python3 -c 'import torch; print(torch.__version__)'
- Identify systems using torch.load() with weights_only=True: grep -r 'weights_only.*True' /path/to/code/
- Search application logs for torch.load() calls followed by unexpected process spawning: grep -E '(torch\.load|exec|subprocess)' /var/log/application.log
- Verify the fix: pip show torch | grep Version and confirm version is 2.6.0 or higher
FAQ
What is CVE-2025-32434?
CVE-2025-32434 is a critical remote code execution vulnerability in PyTorch versions prior to 2.6.0 that allows attackers to execute arbitrary commands when loading a serialized model file, even when the weights_only=True parameter is set. The vulnerability exists in the deserialization process of torch.load().
Is CVE-2025-32434 being actively exploited?
No, CVE-2025-32434 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released. However, given its critical severity, prompt patching is still essential.
What versions of Python are affected by CVE-2025-32434?
PyTorch versions up to and including 2.5.1 are affected. The vulnerability is patched in PyTorch 2.6.0 and later. Note: the vulnerability is in PyTorch, not Python itself, though it affects Python-based ML workflows.
How do I check if my server is vulnerable to CVE-2025-32434?
Run: python3 -c 'import torch; v = torch.__version__.split("."); affected = int(v[0]) < 2 or (int(v[0]) == 2 and int(v[1]) <= 5); print("Vulnerable" if affected else "Not vulnerable")'.
Does Defensia detect CVE-2025-32434?
Yes — Defensia's CVE advisory scanner compares installed PyTorch versions against the NVD database. If PyTorch is installed on a monitored server, CVE-2025-32434 will appear in your dashboard with remediation steps and distro-specific update commands.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-32434. Free for 1 server.
Get started free