Skip to main content
HIGH

CVE-2025-53002

LLaMA-Factory Remote Code Execution (RCE) Vulnerability

CVSS v3

8.3

HIGH

EPSS Score

4.2 %

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, allowing malicious attackers to execute arbitrary malicious code on the host system simply by passing a malicious `Checkpoint path` parameter through the `WebUI` interface. The attack is stealthy, as the

Technical details

CVSS v3 Vector
3.1
Published
2025-06-26
Last Modified
2026-06-17

Frequently asked questions

What is CVE-2025-53002?

LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises because the `vhead_file` is loaded without proper safeguards, allowing malicious attackers to execute arbitrary malicious code on the host system simply by passing a malicious `Checkpoint path` parameter through the `WebUI` interface. The attack is stealthy, as the

Is CVE-2025-53002 actively exploited?

A proof-of-concept exploit exists for CVE-2025-53002, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-53002?

CVE-2025-53002 has a CVSS v3 base score of 8.3 (HIGH severity), with vector string 3.1.

Is CVE-2025-53002 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key