CVE-2025-54949
ExecuTorch heap buffer overflow vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 0.83%
Description
A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit ede82493dae6d2d43f8c424e7be4721abe5242be
How to fix CVE-2025-54949
To remediate CVE-2025-54949, upgrade the affected package to a fixed version below.
- Maven/org.pytorch:executorch-android—upgrade to 0.7.0 or later
- —upgrade to 0.7.0 or later
Is CVE-2025-54949 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.7.0
- from 0, < 0.7.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |