Skip to content
PyTorchPYSEC-2025-196

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

Medium5.5CVE-2025-3121 · Published Apr 2, 2025 · updated May 21, 2026

Source advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
<= 2.6.0-NANo fix yet
Details and references

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
the CVSS score
Also known as
BIT-pytorch-2025-3121, CVE-2025-3121

More PyTorch advisories

All PyTorch

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.