Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

PyTorch is vulnerable to memory corruption through its unpack_sequence function

GHSA-vgrw-7cvw-pwgx · BIT-pytorch-2025-2999 · CVE-2025-2999 · PYSEC-2025-193

Published · Modified

Description

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

A patch is available through commit 4945180.

Ready to move

Start Securing

Free, no credit card | First findings in minutes