CVE-2025-53002
LLaMA-Factory Remote Code Execution (RCE) Vulnerability
CVSS v3
8.3
HIGH
EPSS Score
4.2 %
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
Description
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, allowing malicious attackers to execute arbitrary malicious code on the host system simply by passing a malicious `Checkpoint path` parameter through the `WebUI` interface. The attack is stealthy, as the
Technical details
- CVSS v3 Vector
- 3.1
- Published
- 2025-06-26
- Last Modified
- 2026-06-17
Frequently asked questions
What is CVE-2025-53002?
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, allowing malicious attackers to execute arbitrary malicious code on the host system simply by passing a malicious `Checkpoint path` parameter through the `WebUI` interface. The attack is stealthy, as the
Is CVE-2025-53002 actively exploited?
A proof-of-concept exploit exists for CVE-2025-53002, but active exploitation has not been confirmed at this time.
What is the CVSS score for CVE-2025-53002?
CVE-2025-53002 has a CVSS v3 base score of 8.3 (HIGH severity), with vector string 3.1.
Is CVE-2025-53002 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2025 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).