CVE-2025-54949
CRITICAL9.8EPSS 0.29%ExecuTorch heap buffer overflow vulnerability
Published: 8/8/2025Modified: 5/7/2026
Description
A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493dae6d2d43f8c424e7be4721abe5242be
Affected packages (2)
- Maven/org.pytorch:executorch-androidfrom 0, < 0.7.0
- PyPI/executorchfrom 0, < 0.7.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |