CVE-2025-30404
ExecuTorch integer overflow vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 0.75%
Description
An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit d158236b1dc84539c1b16843bc74054c9dcba006.
How to fix CVE-2025-30404
To remediate CVE-2025-30404, upgrade the affected package to a fixed version below.
- —upgrade to 0.7.0 or later
- —upgrade to 0.7.0 or later
Is CVE-2025-30404 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.7.0
- from 0, < 0.7.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |