vllm is vulnerable to Unsafe Deserialization
75
High Risk
Affected versions of this package are affected by unsafe deserialization due to the use of torch.load with the weights_only parameter set to its default value of False. This function uses pickle for deserialization, which is insecure when handling untrusted data. This vulnerability can lead to arbitrary code execution if a malicious model is loaded. An attacker could exploit this by uploading a harmful model file, affecting unsuspecting users of vLLM.
You are affected if you are using a version that falls within the vulnerable range.
vllm is vulnerable to Unsafe Deserialization in versions 0.3.0 - 0.6.6.
Upgrade the vllm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant