Skip to content
modularGHSA-7xcv-9j6c-2fmc

Modular Max Serve has Unsafe Deserialization vulnerability

CriticalCVE-2025-60455 · Published Nov 18, 2025 · updated Jul 13, 2026

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

GitHub advisory

Affected versions

PackageAffectedFixed in
modular
PyPI
< 25.6.025.6.0
Details and references

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.