CVE-2025-54950
ExecuTorch out-of-bounds access vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 0.97%
Description
An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit fb03b6f85596a8f954d97929075335255b6a58d4.
How to fix CVE-2025-54950
To remediate CVE-2025-54950, upgrade the affected package to a fixed version below.
- —upgrade to 0.7.0 or later
- —upgrade to 0.7.0 or later
Is CVE-2025-54950 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.7.0
- from 0, < 0.7.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |