---
schema_version: '1.0'
id: security-20260711-469b7d
url: https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47
url_hash: 469b7d3a5b88c615f034b5fca39ec2d65453794e4e277408a37c52c0b60f6171
canonical_url: https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2025-3000
- GHSA-rrmf-rvhw-rf47
- severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- torch
- PyPI
lang: en
published_at: '2025-03-31T15:30:48Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-18T06:50:05Z'
status: published
content_hash: 9f9137a941f35aec82b9cc9634e251a52db1c9675dfc7558a99aa34e0b9c7155
license_note: full
summary: PyTorch is vulnerable to memory corruption through its torch.jit.script function
summary_source: rss
summary_en: PyTorch is vulnerable to memory corruption through its torch.jit.script
  function
entities:
- name: PyTorch
  type: artifact
- name: Memory Leak
  type: concept
related_auto:
- name: Imperial Household
  type: organization
  weight: 1.0
- name: Patch
  type: concept
  weight: 1.0
title: 'CVE-2025-3000: PyTorch is vulnerable to memory corruption through its torch.jit.script
  function'
---

# CVE-2025-3000: PyTorch is vulnerable to memory corruption through its torch.jit.script function

## TL;DR
PyTorch is vulnerable to memory corruption through its torch.jit.script function

## Key Points
- cve / CVE-2025-3000 / GHSA-rrmf-rvhw-rf47 / severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L / torch / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
**Advisory:** GHSA-rrmf-rvhw-rf47 (CVE-2025-3000)

**Affected (your watchlist):**
- `PyPI:torch` 2.12.0 → fixed in 2.13.0 [docker/mac]

**Details:**
A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

**References:**
- https://nvd.nist.gov/vuln/detail/CVE-2025-3000
- https://github.com/pytorch/pytorch/issues/149623
- https://github.com/pytorch/pytorch/issues/149623#issue-2935703015
- https://github.com/pytorch/pytorch/commit/b90c94991cdf8b87c8f7439f79518e0ef2c4ca4f
- https://github.com/pypa/advisory-database/tree/main/vulns/torch/PYSEC-2025-194.yaml
- https://github.com/pytorch/pytorch
- https://vuldb.com/?ctiid.302049
- https://vuldb.com/?id.302049
- https://vuldb.com/?submit.524197

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47_

## Source
元記事: [CVE-2025-3000: PyTorch is vulnerable to memory corruption through its torch.jit.script function](https://osv.dev/vulnerability/GHSA-rrmf-rvhw-rf47) — published 2025-03-31T15:30:48Z
