CVE-2025-32434 is a critical remote code execution vulnerability in PyTorch affecting version 2.5.1 and earlier. The flaw is in the torch.load() model-loading functionality and stems from unsafe deserialization of untrusted data. A specially crafted malicious model can trigger code execution during loading, and the issue remains exploitable even when torch.load() is invoked with weights_only=True, a mode that had been considered safer for loading model weights. The vulnerable condition arises when applications or services accept and load attacker-controlled model artifacts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, self-contained proof-of-concept for CVE-2025-32434 targeting PyTorch. It contains two files: a README describing the vulnerability and attack concept, and a single Python script (poc.py) that generates a malicious TorchScript model. The script uses argparse and supports two modes: a function-based TorchScript payload and a class-based torch.nn.Module payload. In both cases, the malicious model uses torch.from_file() to memory-map a target file and copy attacker-controlled bytes into it. The default behavior writes a cron entry to /etc/cron.d/rev containing a bash reverse shell callback to 127.0.0.1:4444. The function-based mode hardcodes both the cron path and payload inside the scripted model, while the class-based mode allows customization of payload text and target file path before serialization. The script saves the resulting model as model.pt by default and, in class mode, optionally verifies loading/execution locally. Overall, the exploit capability is arbitrary file content writing through a malicious serialized PyTorch model, with the demonstrated post-exploitation outcome being persistence and remote shell access via cron. This is exploit code rather than a detector, and it is operational because it includes a concrete payload and model-generation logic.
This repository contains a working exploit for CVE-2025-32434, a remote code execution (RCE) vulnerability in PyTorch versions prior to 2.6.0. The exploit is implemented in a single Python script (CVE-2025-32434-exploit.py) that generates a malicious PyTorch model file. This file, when loaded by a vulnerable version of torch.load() with weights_only=True, will execute arbitrary OS commands on the target system. The exploit leverages Python's pickle deserialization and the __reduce__ method to achieve code execution. The script allows customization of the command to execute and the output filename, and includes an option to test the exploit locally. The README.md provides background on the vulnerability, a description of the exploit's operation, and step-by-step usage instructions. The main attack vector is local: the attacker must convince a victim to load the malicious model file. The exploit does not target network endpoints, but creates or modifies files on the local filesystem as a demonstration of code execution (e.g., /tmp/pwned, /tmp/exploited).
This repository is a proof-of-concept (POC) exploit for CVE-2025-32434, targeting a deserialization vulnerability in PyTorch (specifically version 2.5.0). The exploit consists of a single Python script (exploit.py) that creates a malicious file ('storages') containing a pickle payload designed to execute arbitrary Python code (in this case, printing a message using eval). This file is then archived into 'storages.tar', which is subsequently loaded using torch.load() with weights_only=False, triggering the vulnerability. The exploit demonstrates how an attacker can achieve code execution if a victim loads a crafted tar file in an insecure configuration. The repository also includes a README with technical details and a requirements.txt specifying dependencies. No network endpoints are involved; the attack vector is local file deserialization. The exploit is a POC and does not attempt to bypass security protections enabled in more secure configurations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability referenced as a trending CVE affecting PyTorch (no technical details provided in the content).
Critical remote code execution vulnerability in PyTorch's torch.load() function caused by unsafe deserialization of untrusted data, including cases where weights_only=True was previously considered safe.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.